CVE-2021-40346: Integer Overflow
An integer overflow exists in HAProxy 2.0 through 2.5 in htxaddheader that can be exploited to perform an HTTP request smuggling attack, allowing an attacker to bypass all configured http-request HAProxy ACLs and possibly other ACLs.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/haproxyto a version that resolves this vulnerability.Fixed in 1.8.19-1+deb10u3Fixed in 1.8.19-1+deb10u4Fixed in 2.2.9-2+deb11u5Fixed in 2.6.12-1Fixed in 2.6.15-1
Event History
Frequently Asked Questions
What is the vulnerability ID for this HAProxy integer overflow vulnerability?
The vulnerability ID for this HAProxy integer overflow vulnerability is CVE-2021-40346.
What is the severity of CVE-2021-40346?
CVE-2021-40346 has a severity rating of 7.5 (high).
How does the integer overflow vulnerability in HAProxy 2.0 through 2.5 impact security?
The integer overflow vulnerability in HAProxy 2.0 through 2.5 can be exploited to perform an HTTP request smuggling attack, allowing an attacker to bypass all configured http-request HAProxy ACLs and possibly other ACLs.
Which versions of HAProxy are affected by CVE-2021-40346?
HAProxy versions 2.0 through 2.5 are affected by CVE-2021-40346.
How can I mitigate the CVE-2021-40346 vulnerability in HAProxy?
To mitigate the CVE-2021-40346 vulnerability in HAProxy, upgrade to the fixed versions, such as 1.8.19-1+deb10u3, 1.8.19-1+deb10u4, 2.2.9-2+deb11u5, 2.6.12-1, or 2.6.15-1 depending on your HAProxy version.