cbcvebase.
CVE-2020-11100
published 2020-04-02

CVE-2020-11100: In hpack_dht_insert in hpack-tbl.c in the HPACK decoder in HAProxy 1.8 through 2.x before 2.1.4, a remote attacker can write arbitrary bytes around a certain…

PriorityP273high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
60.73%
99.0th percentile
In hpack_dht_insert in hpack-tbl.c in the HPACK decoder in HAProxy 1.8 through 2.x before 2.1.4, a remote attacker can write arbitrary bytes around a certain location on the heap via a crafted HTTP/2 request, possibly causing remote code execution.

Affected

14 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debianhaproxy< haproxy 2.0.13-2 (bookworm)haproxy 2.0.13-2 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
haproxyhaproxy>= 0 < 2.0.13-22.0.13-2
haproxyhaproxy>= 0 < 2.0.13-22.0.13-2
haproxyhaproxy>= 0 < 2.0.13-22.0.13-2
haproxyhaproxy>= 0 < 2.0.13-22.0.13-2
haproxyhaproxy>= 1.8.0 < 2.1.42.1.4
opensuseleap
redhatopenshift_container_platform
redhatopenshift_container_platform

Detection & IOCsextracted from sources · hover to see the quote

urlhttps://git.haproxy.org/?p=haproxy.git;a=commit;h=5dfc5d5cd0d2128d77253ead3acf03a421ab5b88
pathhpack-tbl.c
  • Detect exploitation attempts by monitoring for crafted HTTP/2 requests targeting HAProxy's HPACK decoder; specifically, anomalous HPACK dynamic header table insertions (hpack_dht_insert) that may indicate out-of-bounds heap write attempts.
  • Check HAProxy configuration files for lines containing 'h2' to determine if HTTP/2 is enabled and the system is exposed to this vulnerability.
  • Monitor for HAProxy process crashes or unexpected memory corruption events, which may indicate active exploitation of this heap write vulnerability via HTTP/2.
  • On Red Hat Enterprise Linux 8, verify SELinux confinement of the haproxy process as a compensating control that may limit the impact of successful exploitation.
  • ·HAProxy versions 1.8 through 2.x before 2.1.4 are vulnerable only when HTTP/2 support is enabled. HAProxy packages on RHEL 6 and 7 do not include HTTP/2 support and are not affected.
  • ·In OpenShift Container Platform 4.x (prior to 4.4), exploitation requires explicitly setting ROUTER_USE_HTTP2 in the OpenShift Ingress Operator, which is not possible by default, reducing the effective risk.
  • ·HTTP/2 is not enabled by default in OpenShift Container Platform 3.11; the configuration option to enable it exists but must be explicitly activated.
  • ·Disabling HTTP/2 protocol support entirely in HAProxy configuration is an effective mitigation for this vulnerability.

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
osv8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.