Input validation error in HAProxy - CVE-2021-39241

 

Input validation error in HAProxy - CVE-2021-39241

Published: August 18, 2021


Vulnerability identifier: #VU55970
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-39241
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to insufficient validation of user-supplied input in HAProxy.  An HTTP method name may contain a space followed by the name of a protected resource. It is possible that a server would interpret this as a request for that protected resource, such as in the "GET /admin? HTTP/1.1 /static/images HTTP/1.1" example.

The attacker can abuse such behavior to bypass implemented security restrictions and perform unauthorized actions against the web application behind the HAProxy.


Affected software

HAProxy
cri-o (Red Hat package)
haproxy (Red Hat package)
haproxy (Debian package)
openshift (Red Hat package)
openshift-kuryr (Red Hat package)
openshift-ansible (Red Hat package)
openshift-clients (Red Hat package)
atomic-openshift-service-idler (Red Hat package)
openstack-ironic (Red Hat package)
ostree (Red Hat package)
haproxy
haproxy-debuginfo
haproxy-debugsource
haproxy-help
Red Hat OpenShift Container Platform
openEuler
Fedora

How to mitigate CVE-2021-39241

Install updates from vendor's website.

HAProxy - addressed in versions 2.0.24, 2.2.16, 2.3.13, 2.4.3
cri-o (Red Hat package) - addressed in versions 1.20.6-5.rhaos4.7.git8594c20.el7, 1.20.6-5.rhaos4.7.git8594c20.el8, 1.22.0-78.rhaos4.9.gitd745cab.el8, 1.22.0-91.rhaos4.9.gitd745cab.el7
haproxy (Red Hat package) - addressed in versions 2.0.16-2.el7, 2.0.16-4.el8, 2.0.19-2.el7, 2.0.19-2.el8, 2.2.13-2.el7, 2.2.13-2.el8, 2.2.15-2.el8
haproxy (Debian package) - update to 2.2.9-2+deb11u1
Red Hat OpenShift Container Platform - addressed in versions 4.6.53, 4.7.41, 4.8.25, 4.9.6
openshift (Red Hat package) - addressed in versions 4.6.0-202112092023.p0.g845f228.assembly.stream.el7, 4.6.0-202112092023.p0.g845f228.assembly.stream.el8, 4.7.0-202201082234.p0.ge880017.assembly.stream.el7, 4.7.0-202201082234.p0.ge880017.assembly.stream.el8, 4.8.0-202112150047.p0.gb4b4813.assembly.stream.el7, 4.8.0-202112150047.p0.gb4b4813.assembly.stream.el8, 4.9.0-202111020225.p0.git.d8c4430.assembly.stream.el7, 4.9.0-202111020225.p0.git.d8c4430.assembly.stream.el8
openshift-kuryr (Red Hat package) - addressed in versions 4.7.0-202201082234.p0.g72de60e.assembly.stream.el8, 4.8.0-202112131630.p0.g839864c.assembly.stream.el8, 4.9.0-202110281423.p0.git.4595a4e.assembly.stream.el8
openshift-ansible (Red Hat package) - update to 4.7.0-202201082234.p0.g4a5273a.assembly.stream.el7
openshift-clients (Red Hat package) - addressed in versions 4.7.0-202201082234.p0.g25914b8.assembly.stream.el7, 4.7.0-202201082234.p0.g25914b8.assembly.stream.el8
atomic-openshift-service-idler (Red Hat package) - update to 4.7.0-202201082234.p0.g39cfc66.assembly.stream.el8
openstack-ironic (Red Hat package) - update to 18.1.1-0.20211019162143.e0437cd.el8
ostree (Red Hat package) - update to 2020.7-6.el8_4
haproxy - update to 2.2.16-1
haproxy-debuginfo - update to 2.2.16-1
haproxy-debugsource - update to 2.2.16-1
haproxy-help - update to 2.2.16-1
haproxy - addressed in versions 2.2.16-1.fc33, 2.3.13-1.fc34

External References

Related Security Bulletins