CRLF injection in HAProxy - CVE-2019-19330

 

CRLF injection in HAProxy - CVE-2019-19330

Published: November 28, 2019


Vulnerability identifier: #VU23084
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-19330
CWE-ID: CWE-93
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform spoofing attack.

The vulnerability exists due to insufficient validation of user-supplied input when processing CRLF and NUL character in the HTTP request, while converting headers from HTTP/2 to HTTP/1. A remote attacker can send a specially crafted HTTP/2 request to the HAProxy and inject arbitrary HTTP headers. Successful exploitation of the vulnerability may allow an attacker to bypass certain security restrictions or perform spoofing attacks.


Affected software

HAProxy
Gentoo Linux
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
haproxy (Debian package)
rh-haproxy18-haproxy (Red Hat package)
haproxy (Alpine package)
haproxy (Ubuntu package)
haproxy (Red Hat package)
Red Hat OpenShift Container Platform
IBM Security Verify Access

How to mitigate CVE-2019-19330

Install updates from vendor's website.

HAProxy - update to 2.0.10
haproxy (Debian package) - addressed in versions 1.8.19-1+deb10u1, 2.0.10-1
rh-haproxy18-haproxy (Red Hat package) - update to 1.8.24-2.el7
haproxy (Alpine package) - update to 1.8.23-r0
haproxy (Ubuntu package) - addressed in versions 1.8.8-1ubuntu0.9, 1.8.19-1ubuntu1.3, 2.0.5-1ubuntu0.3
haproxy (Red Hat package) - addressed in versions 1.8.23-3.el7, 1.8.23-3.el8, 2.0.13-3.el7, 2.0.13-3.el8
Red Hat OpenShift Container Platform - addressed in versions 3.11.0, 4.4.3
IBM Security Verify Access - update to 10.0.7.0

External References

Related Security Bulletins