Hi @alonz22,
I found two security vulnerabilities in haproxy-dashboard v1.3.4.
I'm reporting this responsibly to give you time to fix before public disclosure.
Vulnerability 1 — Missing Authentication (CWE-306) — High
/statistics and /logs are accessible without any authentication.
Vulnerability 2 — Werkzeug Debugger Exposed (CWE-489) — Critical
debug=True on host='::' exposes the interactive debugger publicly.
This allows Remote Code Execution on the server.
Please fix and I will request a CVE with your coordination.
Researcher: Ali Mohammed Kadhim

Hi @alonz22,
I found two security vulnerabilities in haproxy-dashboard v1.3.4.
I'm reporting this responsibly to give you time to fix before public disclosure.
Vulnerability 1 — Missing Authentication (CWE-306) — High
/statistics and /logs are accessible without any authentication.
Vulnerability 2 — Werkzeug Debugger Exposed (CWE-489) — Critical
debug=True on host='::' exposes the interactive debugger publicly.
This allows Remote Code Execution on the server.
Please fix and I will request a CVE with your coordination.
Researcher: Ali Mohammed Kadhim