Inconsistent interpretation of HTTP requests in HAProxy - CVE-2019-18277
Published: November 7, 2019
Vulnerability details
The vulnerability allows a remote attacker to perform HTTP request smuggling attack.
The vulnerability exists due to incorrect processing of messages with a missing transfer-encoding header, when HAProxy is configured in legacy mode. The server does not reject "chunked" value that combined with the "http-reuse always" setting can lead to HTTP request smuggling attack.
Affected software
haproxy (Ubuntu package)
rh-haproxy18-haproxy (Red Hat package)
haproxy (Red Hat package)
Red Hat OpenShift Container Platform
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Opensuse
IBM Security Verify Access
How to mitigate CVE-2019-18277
haproxy (Ubuntu package) - addressed in versions 1.6.3-1ubuntu0.3, 1.8.8-1ubuntu0.7, 1.8.19-1ubuntu1.2, 2.0.5-1ubuntu0.2
rh-haproxy18-haproxy (Red Hat package) - update to 1.8.24-2.el7
haproxy (Red Hat package) - addressed in versions 1.8.23-3.el7, 1.8.23-3.el8, 2.0.13-3.el7, 2.0.13-3.el8
Red Hat OpenShift Container Platform - addressed in versions 3.11.0, 4.4.3
IBM Security Verify Access - update to 10.0.7.0
External References
Related Security Bulletins
- HTTP request smuggling in HAProxy
- Ubuntu update for HAproxy
- OpenSUSE Linux update for haproxy
- OpenSUSE Linux update for haproxy
- Red Hat Enterprise Linux 8 update for haproxy
- Red Hat update for OpenShift Container Platform 4.4.3 haproxy
- Red Hat Software Collections update for rh-haproxy18-haproxy
- Multiple vulnerabilities in IBM Security Verify Access
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 3