In HAProxy (when used with routing release) in Cloud Foundry versions prior to v40.17.0 a critical severity vulnerability CVE-2024-37082 was detected. This vulnerability allows bypass of mTLS authentication to applications hosted on Cloud Foundry. Currently, there is no fix version for this issue. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-37082.
HAProxy: Loophole Allows mTLS Bypass in Cloud Foundry
by the Hossted team
09.07.2024