HMAC Key Vulnerability in HAProxy by HAProxy Technologies
CVE-2019-11323
5.9MEDIUM
What is CVE-2019-11323?
HAProxy versions prior to 1.9.7 exhibit a vulnerability that occurs during the reload process with rotated keys. This flaw results in the use of uninitialized and highly predictable HMAC keys, compromising the integrity of secure communications. The issue is linked to an error in the ssl_sock.h file, which can lead to potentially exploitable scenarios for attackers.