Inconsistent interpretation of HTTP requests in HAProxy - CVE-2019-18277

 

Inconsistent interpretation of HTTP requests in HAProxy - CVE-2019-18277

Published: November 7, 2019


Vulnerability identifier: #VU22597
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-18277
CWE-ID: CWE-444
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform HTTP request smuggling attack.

The vulnerability exists due to incorrect processing of messages with a missing transfer-encoding header, when HAProxy is configured in legacy mode. The server does not reject "chunked" value that combined with the "http-reuse always" setting can lead to HTTP request smuggling attack.


Affected software

HAProxy
haproxy (Ubuntu package)
rh-haproxy18-haproxy (Red Hat package)
haproxy (Red Hat package)
Red Hat OpenShift Container Platform
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Opensuse
IBM Security Verify Access

How to mitigate CVE-2019-18277

Install updates from vendor's website.

HAProxy - update to 2.0.6
haproxy (Ubuntu package) - addressed in versions 1.6.3-1ubuntu0.3, 1.8.8-1ubuntu0.7, 1.8.19-1ubuntu1.2, 2.0.5-1ubuntu0.2
rh-haproxy18-haproxy (Red Hat package) - update to 1.8.24-2.el7
haproxy (Red Hat package) - addressed in versions 1.8.23-3.el7, 1.8.23-3.el8, 2.0.13-3.el7, 2.0.13-3.el8
Red Hat OpenShift Container Platform - addressed in versions 3.11.0, 4.4.3
IBM Security Verify Access - update to 10.0.7.0

External References

Related Security Bulletins