Input validation error in HAProxy - CVE-2021-39240
Published: August 18, 2021
Vulnerability details
The vulnerability allows a remote attacker to bypass security restrictions.
The vulnerability exists due to insufficient validation of user-supplied input when processing HTTP/2 requests. HAProxy does not ensure that the scheme and path portions of a URI have the expected characters, e.g. the authority field on a target HTTP/2 server might differ from what the routing rules were intended to achieve.
A remote attacker can send specially crafted input to the application and bypass implemented security restrictions.
Affected software
cri-o (Red Hat package)
haproxy (Debian package)
haproxy (Red Hat package)
openshift-kuryr (Red Hat package)
openshift (Red Hat package)
openstack-ironic (Red Hat package)
ostree (Red Hat package)
haproxy-help
haproxy-debugsource
haproxy-debuginfo
haproxy
Red Hat OpenShift Container Platform
openEuler
Fedora
How to mitigate CVE-2021-39240
cri-o (Red Hat package) - addressed in versions 1.22.0-78.rhaos4.9.gitd745cab.el8, 1.22.0-91.rhaos4.9.gitd745cab.el7
haproxy (Debian package) - update to 2.2.9-2+deb11u1
haproxy (Red Hat package) - addressed in versions 2.2.13-2.el7, 2.2.13-2.el8, 2.2.15-2.el8
Red Hat OpenShift Container Platform - addressed in versions 4.8.25, 4.9.6
openshift-kuryr (Red Hat package) - addressed in versions 4.8.0-202112131630.p0.g839864c.assembly.stream.el8, 4.9.0-202110281423.p0.git.4595a4e.assembly.stream.el8
openshift (Red Hat package) - addressed in versions 4.8.0-202112150047.p0.gb4b4813.assembly.stream.el7, 4.8.0-202112150047.p0.gb4b4813.assembly.stream.el8, 4.9.0-202111020225.p0.git.d8c4430.assembly.stream.el7, 4.9.0-202111020225.p0.git.d8c4430.assembly.stream.el8
openstack-ironic (Red Hat package) - update to 18.1.1-0.20211019162143.e0437cd.el8
ostree (Red Hat package) - update to 2020.7-6.el8_4
haproxy-help - update to 2.2.16-1
haproxy-debugsource - update to 2.2.16-1
haproxy-debuginfo - update to 2.2.16-1
haproxy - update to 2.2.16-1
haproxy - addressed in versions 2.2.16-1.fc33, 2.3.13-1.fc34