Vulnerability Name: | CVE-2021-40346 (CCN-208856) | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Assigned: | 2021-09-07 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Published: | 2021-09-07 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Updated: | 2021-12-02 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Summary: | An integer overflow exists in HAProxy 2.0 through 2.5 in htx_add_header that can be exploited to perform an HTTP request smuggling attack, allowing an attacker to bypass all configured http-request HAProxy ACLs and possibly other ACLs. | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
CVSS v3 Severity: | 7.5 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N) 6.5 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C)
7.5 High (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N/E:U/RL:O/RC:C)
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N)
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Vulnerability Type: | CWE-190 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2021-40346 Source: CCN Type: HAProxy Web site HAProxy Source: XF Type: UNKNOWN haproxy-cve202140346-request-smuggling(208856) Source: MISC Type: Patch, Vendor Advisory https://git.haproxy.org/?p=haproxy.git Source: MISC Type: Patch, Third Party Advisory https://github.com/haproxy/haproxy/commit/3b69886f7dcc3cfb3d166309018e6cfec9ce2c95 Source: CCN Type: JFrog Web site Critical Vulnerability in HAProxy (CVE-2021-40346): Integer Overflow Enables HTTP Smuggling Source: MISC Type: Exploit, Mitigation, Third Party Advisory https://jfrog.com/blog/critical-vulnerability-in-haproxy-cve-2021-40346-integer-overflow-enables-http-smuggling/ Source: MLIST Type: Mailing List, Third Party Advisory [cloudstack-dev] 20210910 CVE-2021-40346 (haproxy 2.x) Source: MLIST Type: Mailing List, Third Party Advisory [cloudstack-dev] 20210910 Re: CVE-2021-40346 (haproxy 2.x) Source: FEDORA Type: Mailing List, Third Party Advisory FEDORA-2021-3493f9f6ab Source: FEDORA Type: Mailing List, Third Party Advisory FEDORA-2021-cd5ee418f6 Source: CCN Type: The Hacker News Web site HAProxy Found Vulnerable to Critical HTTP Request Smuggling Attack Source: DEBIAN Type: Third Party Advisory DSA-4968 Source: MISC Type: Third Party Advisory https://www.mail-archive.com/haproxy@formilux.org Source: MISC Type: Mitigation, Third Party Advisory https://www.mail-archive.com/haproxy@formilux.org/msg41114.html | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration 3: Denotes that component is vulnerable | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
BACK |