CVE-2021-39241
published 2021-08-17CVE-2021-39241: An issue was discovered in HAProxy 2.0 before 2.0.24, 2.2 before 2.2.16, 2.3 before 2.3.13, and 2.4 before 2.4.3. An HTTP method name may contain a space…
PriorityP430medium5.3CVSS 3.1
AVNACLPRNUINSUCNILAN
EPSS
1.77%
75.8th percentile
An issue was discovered in HAProxy 2.0 before 2.0.24, 2.2 before 2.2.16, 2.3 before 2.3.13, and 2.4 before 2.4.3. An HTTP method name may contain a space followed by the name of a protected resource. It is possible that a server would interpret this as a request for that protected resource, such as in the "GET /admin? HTTP/1.1 /static/images HTTP/1.1" example.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | haproxy | < haproxy 2.2.16-1 (bookworm) | haproxy 2.2.16-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| haproxy | haproxy | >= 0 < 2.2.9-2+deb11u1 | 2.2.9-2+deb11u1 |
| haproxy | haproxy | >= 0 < 2.2.16-1 | 2.2.16-1 |
| haproxy | haproxy | >= 0 < 2.2.16-1 | 2.2.16-1 |
| haproxy | haproxy | >= 0 < 2.2.16-1 | 2.2.16-1 |
| haproxy | haproxy | >= 2.0.0 < 2.0.24 | 2.0.24 |
| haproxy | haproxy | >= 2.2.0 < 2.2.16 | 2.2.16 |
| haproxy | haproxy | >= 2.3.0 < 2.3.13 | 2.3.13 |
| haproxy | haproxy | >= 2.4.0 < 2.4.3 | 2.4.3 |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv5.3MEDIUM
vendor_debian5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6x47-wc8c-3q36: An issue was discovered in HAProxy 2
ghsa_unreviewed·2022-05-24
CVE-2021-39241 [MEDIUM] GHSA-6x47-wc8c-3q36: An issue was discovered in HAProxy 2
An issue was discovered in HAProxy 2.0 before 2.0.24, 2.2 before 2.2.16, 2.3 before 2.3.13, and 2.4 before 2.4.3. An HTTP method name may contain a space followed by the name of a protected resource. It is possible that a server would interpret this as a request for that protected resource, such as in the "GET /admin? HTTP/1.1 /static/images HTTP/1.1" example.
OSV
CVE-2021-39241: An issue was discovered in HAProxy 2
osv·2021-08-17·CVSS 5.3
CVE-2021-39241 [MEDIUM] CVE-2021-39241: An issue was discovered in HAProxy 2
An issue was discovered in HAProxy 2.0 before 2.0.24, 2.2 before 2.2.16, 2.3 before 2.3.13, and 2.4 before 2.4.3. An HTTP method name may contain a space followed by the name of a protected resource. It is possible that a server would interpret this as a request for that protected resource, such as in the "GET /admin? HTTP/1.1 /static/images HTTP/1.1" example.
Red Hat
haproxy: an HTTP method name may contain a space followed by the name of a protected resource
vendor_redhat·2021-08-17·CVSS 5.3
CVE-2021-39241 [MEDIUM] CWE-20 haproxy: an HTTP method name may contain a space followed by the name of a protected resource
haproxy: an HTTP method name may contain a space followed by the name of a protected resource
An issue was discovered in HAProxy 2.0 before 2.0.24, 2.2 before 2.2.16, 2.3 before 2.3.13, and 2.4 before 2.4.3. An HTTP method name may contain a space followed by the name of a protected resource. It is possible that a server would interpret this as a request for that protected resource, such as in the "GET /admin? HTTP/1.1 /static/images HTTP/1.1" example.
haproxy has an input validation flaw that could allow a remote attacker to bypass implemented security restrictions. An HTTP method name may contain a space followed by the name of a protected resource. Given this, It is possible that an server would interpret this as a request for that protected resource. The highest threat from this vuln
Debian
CVE-2021-39241: haproxy - An issue was discovered in HAProxy 2.0 before 2.0.24, 2.2 before 2.2.16, 2.3 bef...
vendor_debian·2021·CVSS 5.3
CVE-2021-39241 [MEDIUM] CVE-2021-39241: haproxy - An issue was discovered in HAProxy 2.0 before 2.0.24, 2.2 before 2.2.16, 2.3 bef...
An issue was discovered in HAProxy 2.0 before 2.0.24, 2.2 before 2.2.16, 2.3 before 2.3.13, and 2.4 before 2.4.3. An HTTP method name may contain a space followed by the name of a protected resource. It is possible that a server would interpret this as a request for that protected resource, such as in the "GET /admin? HTTP/1.1 /static/images HTTP/1.1" example.
Scope: local
bookworm: resolved (fixed in 2.2.16-1)
bullseye: resolved (fixed in 2.2.9-2+deb11u1)
forky: resolved (fixed in 2.2.16-1)
sid: resolved (fixed in 2.2.16-1)
trixie: resolved (fixed in 2.2.16-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://git.haproxy.org/?p=haproxy.git%3Ba=commit%3Bh=89265224d314a056d77d974284802c1b8a0dc97fhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4ALECUZDIMT5FYGP6V6PVSI4BKVZTZWN/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RPNY4WZIQUAUOCLIMUPC37AQWNXTWIQM/https://www.debian.org/security/2021/dsa-4960https://www.mail-archive.com/haproxy%40formilux.org/msg41041.htmlhttps://git.haproxy.org/?p=haproxy.git%3Ba=commit%3Bh=89265224d314a056d77d974284802c1b8a0dc97fhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4ALECUZDIMT5FYGP6V6PVSI4BKVZTZWN/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RPNY4WZIQUAUOCLIMUPC37AQWNXTWIQM/https://www.debian.org/security/2021/dsa-4960https://www.mail-archive.com/haproxy%40formilux.org/msg41041.html
2021-08-17
Published