Input validation error in HAProxy - CVE-2021-39242
Published: August 18, 2021
Vulnerability identifier: #VU55971
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-39242
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists due to insufficient validation of user-supplied input when processing HTTP headers. A remote attacker can send a specially crafted Host header to the application and bypass implemented security restrictions.
Affected software
HAProxy
cri-o (Red Hat package)
haproxy (Debian package)
haproxy (Red Hat package)
openshift-kuryr (Red Hat package)
openshift (Red Hat package)
openstack-ironic (Red Hat package)
ostree (Red Hat package)
haproxy-help
haproxy-debugsource
haproxy-debuginfo
haproxy
Red Hat OpenShift Container Platform
openEuler
Fedora
cri-o (Red Hat package)
haproxy (Debian package)
haproxy (Red Hat package)
openshift-kuryr (Red Hat package)
openshift (Red Hat package)
openstack-ironic (Red Hat package)
ostree (Red Hat package)
haproxy-help
haproxy-debugsource
haproxy-debuginfo
haproxy
Red Hat OpenShift Container Platform
openEuler
Fedora
How to mitigate CVE-2021-39242
Install updates from vendor's website.
HAProxy - addressed in versions 2.2.16, 2.3.13, 2.4.3
cri-o (Red Hat package) - addressed in versions 1.22.0-78.rhaos4.9.gitd745cab.el8, 1.22.0-91.rhaos4.9.gitd745cab.el7
haproxy (Debian package) - update to 2.2.9-2+deb11u1
haproxy (Red Hat package) - addressed in versions 2.2.13-2.el7, 2.2.13-2.el8, 2.2.15-2.el8
Red Hat OpenShift Container Platform - addressed in versions 4.8.25, 4.9.6
openshift-kuryr (Red Hat package) - addressed in versions 4.8.0-202112131630.p0.g839864c.assembly.stream.el8, 4.9.0-202110281423.p0.git.4595a4e.assembly.stream.el8
openshift (Red Hat package) - addressed in versions 4.8.0-202112150047.p0.gb4b4813.assembly.stream.el7, 4.8.0-202112150047.p0.gb4b4813.assembly.stream.el8, 4.9.0-202111020225.p0.git.d8c4430.assembly.stream.el7, 4.9.0-202111020225.p0.git.d8c4430.assembly.stream.el8
openstack-ironic (Red Hat package) - update to 18.1.1-0.20211019162143.e0437cd.el8
ostree (Red Hat package) - update to 2020.7-6.el8_4
haproxy-help - update to 2.2.16-1
haproxy-debugsource - update to 2.2.16-1
haproxy-debuginfo - update to 2.2.16-1
haproxy - update to 2.2.16-1
haproxy - addressed in versions 2.2.16-1.fc33, 2.3.13-1.fc34
cri-o (Red Hat package) - addressed in versions 1.22.0-78.rhaos4.9.gitd745cab.el8, 1.22.0-91.rhaos4.9.gitd745cab.el7
haproxy (Debian package) - update to 2.2.9-2+deb11u1
haproxy (Red Hat package) - addressed in versions 2.2.13-2.el7, 2.2.13-2.el8, 2.2.15-2.el8
Red Hat OpenShift Container Platform - addressed in versions 4.8.25, 4.9.6
openshift-kuryr (Red Hat package) - addressed in versions 4.8.0-202112131630.p0.g839864c.assembly.stream.el8, 4.9.0-202110281423.p0.git.4595a4e.assembly.stream.el8
openshift (Red Hat package) - addressed in versions 4.8.0-202112150047.p0.gb4b4813.assembly.stream.el7, 4.8.0-202112150047.p0.gb4b4813.assembly.stream.el8, 4.9.0-202111020225.p0.git.d8c4430.assembly.stream.el7, 4.9.0-202111020225.p0.git.d8c4430.assembly.stream.el8
openstack-ironic (Red Hat package) - update to 18.1.1-0.20211019162143.e0437cd.el8
ostree (Red Hat package) - update to 2020.7-6.el8_4
haproxy-help - update to 2.2.16-1
haproxy-debugsource - update to 2.2.16-1
haproxy-debuginfo - update to 2.2.16-1
haproxy - update to 2.2.16-1
haproxy - addressed in versions 2.2.16-1.fc33, 2.3.13-1.fc34