CRLF injection in HAProxy - CVE-2019-19330
Published: November 28, 2019
Vulnerability details
The vulnerability allows a remote attacker to perform spoofing attack.
The vulnerability exists due to insufficient validation of user-supplied input when processing CRLF and NUL character in the HTTP request, while converting headers from HTTP/2 to
HTTP/1. A remote attacker can send a specially crafted HTTP/2 request to the HAProxy and inject arbitrary HTTP headers. Successful exploitation of the vulnerability may allow an attacker to bypass certain security restrictions or perform spoofing attacks.
Affected software
Gentoo Linux
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
haproxy (Debian package)
rh-haproxy18-haproxy (Red Hat package)
haproxy (Alpine package)
haproxy (Ubuntu package)
haproxy (Red Hat package)
Red Hat OpenShift Container Platform
IBM Security Verify Access
How to mitigate CVE-2019-19330
haproxy (Debian package) - addressed in versions 1.8.19-1+deb10u1, 2.0.10-1
rh-haproxy18-haproxy (Red Hat package) - update to 1.8.24-2.el7
haproxy (Alpine package) - update to 1.8.23-r0
haproxy (Ubuntu package) - addressed in versions 1.8.8-1ubuntu0.9, 1.8.19-1ubuntu1.3, 2.0.5-1ubuntu0.3
haproxy (Red Hat package) - addressed in versions 1.8.23-3.el7, 1.8.23-3.el8, 2.0.13-3.el7, 2.0.13-3.el8
Red Hat OpenShift Container Platform - addressed in versions 3.11.0, 4.4.3
IBM Security Verify Access - update to 10.0.7.0
External References
- https://git.haproxy.org/?p=haproxy.git;a=commit;h=146f53ae7e97dbfe496d0445c2802dd0a30b0878
- https://git.haproxy.org/?p=haproxy.git;a=commit;h=54f53ef7ce4102be596130b44c768d1818570344
- https://git.haproxy.org/?p=haproxy-2.0.git;a=commit;h=ac198b92d461515551b95daae20954b3053ce87e
- https://tools.ietf.org/html/rfc7540#section-10.3
Related Security Bulletins
- CRLF injection in HAProxy
- Debian update for haproxy
- Ubuntu update for HAProxy
- Gentoo update for HAProxy
- Red Hat Enterprise Linux 8 update for haproxy
- Red Hat update for OpenShift Container Platform 4.4.3 haproxy
- Red Hat Software Collections update for rh-haproxy18-haproxy
- CRLF injection in haproxy (Alpine package)
- Multiple vulnerabilities in IBM Security Verify Access
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 3