QID 670973
Date Published: 2021-11-24
QID 670973: EulerOS Security Update for haproxy (EulerOS-SA-2021-2687)
HAProxy is a free, very fast and reliable solution offering high availability, load balancing,and proxying for TCP and HTTP-based applications. It is particularly suited for very high traffic web sites and powers quite a number of the world's most visited ones.
Security Fix(es):
An issue was discovered in HAProxy 2.0 before 2.0.24, 2.2 before 2.2.16, 2.3 before 2.3.13, and 2.4 before 2.4.3. An HTTP method name may contain a space followed by the name of a protected resource. It is possible that a server would interpret this as a request for that protected resource, such as in the "GET /admin? HTTP/1.1 /static/images HTTP/1.1" example.(CVE-2021-39241)
An issue was discovered in HAProxy 2.2 before 2.2.16, 2.3 before 2.3.13, and 2.4 before 2.4.3. It can lead to a situation with an attacker-controlled HTTP Host header, because a mismatch between Host and authority is mishandled.(CVE-2021-39242)
Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.
An arbitrary attacker may exploit this vulnerability to compromise the system.
CVEs related to QID 670973
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| EulerOS-SA-2021-2687 | EulerOS V2.0SP9 |
|