Input validation error in HAProxy - CVE-2021-39241
Published: August 18, 2021
Vulnerability details
The vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists due to insufficient validation of user-supplied input in HAProxy. An HTTP method name may contain a space followed by the name of a protected resource. It is possible that a server would interpret this as a request for that protected resource, such as in the "GET /admin? HTTP/1.1 /static/images HTTP/1.1" example.
The attacker can abuse such behavior to bypass implemented security restrictions and perform unauthorized actions against the web application behind the HAProxy.
Affected software
cri-o (Red Hat package)
haproxy (Red Hat package)
haproxy (Debian package)
openshift (Red Hat package)
openshift-kuryr (Red Hat package)
openshift-ansible (Red Hat package)
openshift-clients (Red Hat package)
atomic-openshift-service-idler (Red Hat package)
openstack-ironic (Red Hat package)
ostree (Red Hat package)
haproxy
haproxy-debuginfo
haproxy-debugsource
haproxy-help
Red Hat OpenShift Container Platform
openEuler
Fedora
How to mitigate CVE-2021-39241
cri-o (Red Hat package) - addressed in versions 1.20.6-5.rhaos4.7.git8594c20.el7, 1.20.6-5.rhaos4.7.git8594c20.el8, 1.22.0-78.rhaos4.9.gitd745cab.el8, 1.22.0-91.rhaos4.9.gitd745cab.el7
haproxy (Red Hat package) - addressed in versions 2.0.16-2.el7, 2.0.16-4.el8, 2.0.19-2.el7, 2.0.19-2.el8, 2.2.13-2.el7, 2.2.13-2.el8, 2.2.15-2.el8
haproxy (Debian package) - update to 2.2.9-2+deb11u1
Red Hat OpenShift Container Platform - addressed in versions 4.6.53, 4.7.41, 4.8.25, 4.9.6
openshift (Red Hat package) - addressed in versions 4.6.0-202112092023.p0.g845f228.assembly.stream.el7, 4.6.0-202112092023.p0.g845f228.assembly.stream.el8, 4.7.0-202201082234.p0.ge880017.assembly.stream.el7, 4.7.0-202201082234.p0.ge880017.assembly.stream.el8, 4.8.0-202112150047.p0.gb4b4813.assembly.stream.el7, 4.8.0-202112150047.p0.gb4b4813.assembly.stream.el8, 4.9.0-202111020225.p0.git.d8c4430.assembly.stream.el7, 4.9.0-202111020225.p0.git.d8c4430.assembly.stream.el8
openshift-kuryr (Red Hat package) - addressed in versions 4.7.0-202201082234.p0.g72de60e.assembly.stream.el8, 4.8.0-202112131630.p0.g839864c.assembly.stream.el8, 4.9.0-202110281423.p0.git.4595a4e.assembly.stream.el8
openshift-ansible (Red Hat package) - update to 4.7.0-202201082234.p0.g4a5273a.assembly.stream.el7
openshift-clients (Red Hat package) - addressed in versions 4.7.0-202201082234.p0.g25914b8.assembly.stream.el7, 4.7.0-202201082234.p0.g25914b8.assembly.stream.el8
atomic-openshift-service-idler (Red Hat package) - update to 4.7.0-202201082234.p0.g39cfc66.assembly.stream.el8
openstack-ironic (Red Hat package) - update to 18.1.1-0.20211019162143.e0437cd.el8
ostree (Red Hat package) - update to 2020.7-6.el8_4
haproxy - update to 2.2.16-1
haproxy-debuginfo - update to 2.2.16-1
haproxy-debugsource - update to 2.2.16-1
haproxy-help - update to 2.2.16-1
haproxy - addressed in versions 2.2.16-1.fc33, 2.3.13-1.fc34
External References
Related Security Bulletins
- Multiple vulnerabilities in HAProxy
- Debian update for haproxy
- Multiple vulnerabilities in OpenShift Container Platform 4.9
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.8
- Red Hat OpenShift Container Platform update for haproxy
- Red Hat OpenShift Container Platform update for Apache Log4j
- Multiple vulnerabilities in OpenShift Container Platform 4.7
- openEuler update for haproxy
- Fedora 34 update for haproxy
- Fedora 33 update for haproxy