PT-2024-7969 · Haproxy+1 · Haproxy+1
Christian Schubert
·
Published
2024-06-24
·
Updated
2024-07-12
·
CVE-2024-37082
CVSS v3.1
9.4
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Cloud Foundry versions prior to 40.17.0
Description
The issue is related to a security check loophole in the HAProxy release when used in combination with the routing release in Cloud Foundry. This might allow an attacker to craft HTTP requests that bypass mTLS authentication to Cloud Foundry applications. The vulnerability is associated with the HAProxy component and can be exploited by spoofing, potentially allowing a remote attacker to bypass authentication checks.
Recommendations
For Cloud Foundry versions prior to 40.17.0, update to version 40.17.0 or later to resolve the issue.
As a temporary workaround, consider disabling the route-services in routing-release or reconfiguring the haproxy-boshrelease property
ha proxy.forwarded client cert to a value other than forward only if route service until a patch is applied.Fix
Authentication Bypass by Spoofing
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cloud Foundry
Haproxy