CVE Vulnerabilities

CVE-2021-39242

Improper Handling of Exceptional Conditions

Published: Aug 17, 2021 | Modified: Nov 21, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
7.5 MODERATE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Ubuntu
MEDIUM

An issue was discovered in HAProxy 2.2 before 2.2.16, 2.3 before 2.3.13, and 2.4 before 2.4.3. It can lead to a situation with an attacker-controlled HTTP Host header, because a mismatch between Host and authority is mishandled.

Weakness

The product does not handle or incorrectly handles an exceptional condition.

Affected Software

Name Vendor Start Version End Version
Haproxy Haproxy 2.2.0 (including) 2.2.16 (excluding)
Haproxy Haproxy 2.3.0 (including) 2.3.13 (excluding)
Haproxy Haproxy 2.4.0 (including) 2.4.3 (excluding)
Haproxy Ubuntu devel *
Haproxy Ubuntu hirsute *
Haproxy Ubuntu impish *
Haproxy Ubuntu jammy *
Haproxy Ubuntu trusty *
Haproxy Ubuntu xenial *
Red Hat OpenShift Container Platform 4.8 RedHat haproxy-0:2.2.13-2.el8 *
Red Hat OpenShift Container Platform 4.9 RedHat haproxy-0:2.2.15-2.el8 *

References