CVE-2021-39242
published 2021-08-17CVE-2021-39242: An issue was discovered in HAProxy 2.2 before 2.2.16, 2.3 before 2.3.13, and 2.4 before 2.4.3. It can lead to a situation with an attacker-controlled HTTP Host…
PriorityP339high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
EPSS
2.34%
81.8th percentile
An issue was discovered in HAProxy 2.2 before 2.2.16, 2.3 before 2.3.13, and 2.4 before 2.4.3. It can lead to a situation with an attacker-controlled HTTP Host header, because a mismatch between Host and authority is mishandled.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | haproxy | < haproxy 2.2.16-1 (bookworm) | haproxy 2.2.16-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| haproxy | haproxy | >= 0 < 2.2.9-2+deb11u1 | 2.2.9-2+deb11u1 |
| haproxy | haproxy | >= 0 < 2.2.16-1 | 2.2.16-1 |
| haproxy | haproxy | >= 0 < 2.2.16-1 | 2.2.16-1 |
| haproxy | haproxy | >= 0 < 2.2.16-1 | 2.2.16-1 |
| haproxy | haproxy | >= 2.2.0 < 2.2.16 | 2.2.16 |
| haproxy | haproxy | >= 2.3.0 < 2.3.13 | 2.3.13 |
| haproxy | haproxy | >= 2.4.0 < 2.4.3 | 2.4.3 |
| redhat | openshift | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-gh3m-9h22-r3r5: An issue was discovered in HAProxy 2
ghsa_unreviewed·2022-05-24
CVE-2021-39242 [HIGH] CWE-755 GHSA-gh3m-9h22-r3r5: An issue was discovered in HAProxy 2
An issue was discovered in HAProxy 2.2 before 2.2.16, 2.3 before 2.3.13, and 2.4 before 2.4.3. It can lead to a situation with an attacker-controlled HTTP Host header, because a mismatch between Host and authority is mishandled.
GHSA
GHSA-v3g6-gh83-x752: The release of OpenShift 4
ghsa_unreviewed·2022-04-12·CVSS 7.5
CVE-2021-4047 [HIGH] CWE-20 GHSA-v3g6-gh83-x752: The release of OpenShift 4
The release of OpenShift 4.9.6 included four CVE fixes for the haproxy package, however the patch for CVE-2021-39242 was missing. This issue only affects Red Hat OpenShift 4.9.
OSV
CVE-2021-39242: An issue was discovered in HAProxy 2
osv·2021-08-17·CVSS 7.5
CVE-2021-39242 [HIGH] CVE-2021-39242: An issue was discovered in HAProxy 2
An issue was discovered in HAProxy 2.2 before 2.2.16, 2.3 before 2.3.13, and 2.4 before 2.4.3. It can lead to a situation with an attacker-controlled HTTP Host header, because a mismatch between Host and authority is mishandled.
Red Hat
haproxy: Incomplete fix for CVE-2021-39242 in OpenShift 4.9
vendor_redhat·2021-11-30·CVSS 7.5
CVE-2021-4047 [HIGH] CWE-20 haproxy: Incomplete fix for CVE-2021-39242 in OpenShift 4.9
haproxy: Incomplete fix for CVE-2021-39242 in OpenShift 4.9
The release of OpenShift 4.9.6 included four CVE fixes for the haproxy package, however the patch for CVE-2021-39242 was missing. This issue only affects Red Hat OpenShift 4.9.
The release of OpenShift 4.9.6 included four CVE fixes for the haproxy package, however the patch for CVE-2021-39242 was missing. This issue was only affects OpenShift 4.9.
Statement: The fix for the original CVE is correctly included in OpenShift 4.9.11.
Package: haproxy (Red Hat Enterprise Linux 7) - Not affected
Package: haproxy (Red Hat Enterprise Linux 8) - Not affected
Package: haproxy (Red Hat Enterprise Linux 9) - Not affected
Package: haproxy (Red Hat OpenShift Container Platform 3.11) - Not affected
Package: rh-haproxy18-haproxy (Red Hat S
Red Hat
haproxy: it can lead to a situation with an attacker-controlled HTTP Host header because a mismatch between Host and authority is mishandled
vendor_redhat·2021-08-17·CVSS 7.5
CVE-2021-39242 [HIGH] CWE-20 haproxy: it can lead to a situation with an attacker-controlled HTTP Host header because a mismatch between Host and authority is mishandled
haproxy: it can lead to a situation with an attacker-controlled HTTP Host header because a mismatch between Host and authority is mishandled
An issue was discovered in HAProxy 2.2 before 2.2.16, 2.3 before 2.3.13, and 2.4 before 2.4.3. It can lead to a situation with an attacker-controlled HTTP Host header, because a mismatch between Host and authority is mishandled.
haproxy was found to be vulnerable to HTTP host header attack: This problem creates a scenario in which it's possible to drop the Host header and use the authority only after forwarding to a
second http2 layer, possibly causing two differing values of Host at a different stage. The highest threat from this vulnerability is data integrity.
Package: haproxy (Red Hat Enterprise Linux 6) - Not affected
Package: haproxy (Red Ha
Debian
CVE-2021-39242: haproxy - An issue was discovered in HAProxy 2.2 before 2.2.16, 2.3 before 2.3.13, and 2.4...
vendor_debian·2021·CVSS 7.5
CVE-2021-39242 [HIGH] CVE-2021-39242: haproxy - An issue was discovered in HAProxy 2.2 before 2.2.16, 2.3 before 2.3.13, and 2.4...
An issue was discovered in HAProxy 2.2 before 2.2.16, 2.3 before 2.3.13, and 2.4 before 2.4.3. It can lead to a situation with an attacker-controlled HTTP Host header, because a mismatch between Host and authority is mishandled.
Scope: local
bookworm: resolved (fixed in 2.2.16-1)
bullseye: resolved (fixed in 2.2.9-2+deb11u1)
forky: resolved (fixed in 2.2.16-1)
sid: resolved (fixed in 2.2.16-1)
trixie: resolved (fixed in 2.2.16-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://git.haproxy.org/?p=haproxy.git%3Ba=commit%3Bh=b5d2b9e154d78e4075db163826c5e0f6d31b2ab1https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4ALECUZDIMT5FYGP6V6PVSI4BKVZTZWN/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RPNY4WZIQUAUOCLIMUPC37AQWNXTWIQM/https://www.debian.org/security/2021/dsa-4960https://www.mail-archive.com/haproxy%40formilux.org/msg41041.htmlhttps://git.haproxy.org/?p=haproxy.git%3Ba=commit%3Bh=b5d2b9e154d78e4075db163826c5e0f6d31b2ab1https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4ALECUZDIMT5FYGP6V6PVSI4BKVZTZWN/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RPNY4WZIQUAUOCLIMUPC37AQWNXTWIQM/https://www.debian.org/security/2021/dsa-4960https://www.mail-archive.com/haproxy%40formilux.org/msg41041.html
2021-08-17
Published