CVE-2023-0056: Fedoraproject Extra Packages For Enterprise Linux
Medium severity, CVSS 6.5. EPSS: 1.8% chance of exploitation in the next 30 days.
An uncontrolled resource consumption vulnerability was discovered in HAProxy which could crash the service. This issue could allow an authenticated remote attacker to run a specially crafted malicious server in an OpenShift cluster. The biggest impact is to availability.
Affected products
- Fedoraproject Extra Packages For Enterprise Linux: version 8.0 only
- Fedoraproject Fedora: version 36 only; version 37 only
- Haproxy Haproxy: affected versions not specified
- Red Hat Ceph Storage: version 5.0 only
- Red Hat Openshift Container Platform: version 4.12 only; version 4.10 only; version 4.11 only
- Red Hat Openshift Container Platform For IBM Linuxone: version 4.12 only; version 4.10 only; version 4.11 only
- Red Hat Openshift Container Platform For Power: version 4.12 only; version 4.10 only; version 4.11 only
- Red Hat Openshift Container Platform IBM Z Systems: version 4.12 only; version 4.10 only; version 4.11 only
- Red Hat Software Collections: affected versions not specified
Published 2023-03-23. Last modified 2026-06-17.