CVE Vulnerabilities

CVE-2021-39242

Improper Handling of Exceptional Conditions

Published: Aug 17, 2021 | Modified: Nov 21, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
7.5 MODERATE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

An issue was discovered in HAProxy 2.2 before 2.2.16, 2.3 before 2.3.13, and 2.4 before 2.4.3. It can lead to a situation with an attacker-controlled HTTP Host header, because a mismatch between Host and authority is mishandled.

Weakness

The product does not handle or incorrectly handles an exceptional condition.

Affected Software

NameVendorStart VersionEnd Version
HaproxyHaproxy2.2.0 (including)2.2.16 (excluding)
HaproxyHaproxy2.3.0 (including)2.3.13 (excluding)
HaproxyHaproxy2.4.0 (including)2.4.3 (excluding)
Red Hat OpenShift Container Platform 4.8RedHathaproxy-0:2.2.13-2.el7*
Red Hat OpenShift Container Platform 4.9RedHathaproxy-0:2.2.15-2.el8*
HaproxyUbuntudevel*
HaproxyUbuntuhirsute*
HaproxyUbuntuimpish*
HaproxyUbuntujammy*
HaproxyUbuntutrusty*
HaproxyUbuntuxenial*

References