HAProxy stats panel exposed externally

Disclosed: 2023-03-24 17:25:49 By kalkii To deptofdefense
Medium
Vulnerability Details
Hi Team I was able to find exposed web panel for HAProxy running on ████at port 1024 ## Impact By visiting http://██████:1024/haproxy-status, the statistics page for HAProxy is shown. I have attached a screenshot to confirm that the endpoint is accessible externally ███ ## System Host(s) ████ ## Affected Product(s) and Version(s) ## CVE Numbers ## Steps to Reproduce To Reproduce this simply visit http://███:1024/haproxy-status?stats http://███:1024/haproxy-status ## Suggested Mitigation/Remediation Actions
Actions
View on HackerOne
Report Stats
  • Report ID: 1884372
  • State: Closed
  • Substate: resolved
  • Upvotes: 7
Share this report