PT-2024-7691 · Haproxy+2 · Haproxy+2

Michael Wedl

·

Published

2024-10-13

·

Updated

2024-10-29

·

CVE-2024-49214

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions HAProxy versions 2.9.x through 2.9.10 HAProxy versions 3.0.x through 3.0.4 HAProxy versions 3.1.x through 3.1-dev6
Description The issue allows an attacker to open a 0-RTT session with a spoofed IP address, bypassing the IP allow/block list functionality. This can be exploited by a remote attacker to bypass authentication. The vulnerability is related to the QUIC protocol in HAProxy.
Recommendations For HAProxy versions 2.9.x through 2.9.10, update to version 2.9.11 to resolve the issue. For HAProxy versions 3.0.x through 3.0.4, update to version 3.0.5 to resolve the issue. For HAProxy versions 3.1.x through 3.1-dev6, update to version 3.1-dev7 or later to resolve the issue. As a temporary workaround, consider restricting access to the QUIC protocol until a patch is available.

Fix

Authentication Bypass by Spoofing

Weakness Enumeration

Related Identifiers

AZL-50333
BDU:2024-09148
BIT-HAPROXY-2024-49214
CVE-2024-49214
OESA-2024-2273
OPENSUSE-SU-2024:14402-1

Affected Products

Debian
Haproxy
Red Os