3 ms·
The article is really poor and not original, doesn't link to haproxy or jfrog web pages or haproxy git repo. Please link the original jfrog blog post with in d
by nezirus 5y ago
The article is really poor and not original, doesn't link to haproxy or jfrog web pages or haproxy git repo.
Please link the original jfrog blog post with in depth analysis:
https://jfrog.com/blog/critical-vulnerability-in-haproxy-cve-2021-40346-integer-overflow-enables-http-smuggling/ https://jfrog.com/blog/critical-vulnerability-in-haproxy-cve...
- sciurus 5y agoAgreed jfrog has the more in-depth exploration in this case. Still, James Kettle from Portswigger has donegood work in this area; I'd recommend anyone who's not familiar with HTTP request smuggling read https://portswigger.net/research/http-desync-attacks-request-smuggling-reborn https://portswigger.net/research/http-desync-attacks-request...