CVE-2021-39242
Summary
| CVE | CVE-2021-39242 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-08-17 19:15:00 UTC |
| Updated | 2023-11-07 03:37:00 UTC |
| Description | An issue was discovered in HAProxy 2.2 before 2.2.16, 2.3 before 2.3.13, and 2.4 before 2.4.3. It can lead to a situation with an attacker-controlled HTTP Host header, because a mismatch between Host and authority is mishandled. |
NVD Known Affected Configurations (CPE 2.3)
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 181961 Debian Security Update for haproxy (CVE-2021-39242)
- 239873 Red Hat OpenShift Container Platform 4.9 Security Update (RHSA-2021:4118)
- 239987 Red Hat OpenShift Container Platform 4.8 Security Update (RHSA-2021:5208)
- 281856 Fedora Security Update for haproxy (FEDORA-2021-3ab4512c98)
- 281857 Fedora Security Update for haproxy (FEDORA-2021-e6557245e8)
- 356275 Amazon Linux Security Advisory for haproxy2 : ALASHAPROXY2-2023-005
- 356499 Amazon Linux Security Advisory for haproxy2 : ALAS2HAPROXY2-2023-005
- 670836 EulerOS Security Update for haproxy (EulerOS-SA-2021-2712)
- 670973 EulerOS Security Update for haproxy (EulerOS-SA-2021-2687)
- 770124 Red Hat OpenShift Container Platform 4.9 Security Update (RHSA-2021:4118)
- 770130 Red Hat OpenShift Container Platform 4.8 Security Update (RHSA-2021:5208)