PT-2021-7493 · Haproxy+2 · Haproxy+2

Tim Düsterhus

·

Published

2021-08-11

·

Updated

2024-03-06

·

CVE-2021-39242

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions HAProxy versions 2.2 before 2.2.16 HAProxy versions 2.3 before 2.3.13 HAProxy versions 2.4 before 2.4.3
Description The issue is related to a mismatch between Host and authority being mishandled, which can lead to an attacker-controlled HTTP Host header. This can allow a remote attacker to impact data integrity.
Recommendations For HAProxy versions 2.2 before 2.2.16, update to version 2.2.16 or later. For HAProxy versions 2.3 before 2.3.13, update to version 2.3.13 or later. For HAProxy versions 2.4 before 2.4.3, update to version 2.4.3 or later.

Exploit

Fix

Improper Handling of Exceptional Conditions

Weakness Enumeration

Related Identifiers

ALT-PU-2022-3040
ALT-PU-2023-1151
BDU:2022-06897
BIT-HAPROXY-2021-39242
CVE-2021-39242
DSA-4960-1
OESA-2021-1333
RHSA-2021:4118
RHSA-2021:5208

Affected Products

Alt Linux
Astra Linux
Haproxy