CVE-2024-37082: HAProxy Authentication Bypass
When deploying Cloud Foundry together with the haproxy-boshrelease and using a non default configuration, it might be possible to craft HTTP requests that bypass mTLS authentication to Cloud Foundry applications.
You are affected if you have route-services enabled in routing-release and have configured the haproxy-boshrelease property “haproxy.forwardedclientcert” to “forwardonlyifrouteservice”.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-37082?
CVE-2024-37082 is considered a significant vulnerability due to the potential to bypass mTLS authentication.
How do I fix CVE-2024-37082?
To mitigate CVE-2024-37082, ensure that your HAProxy and routing releases are configured to default settings and apply any patches provided by Cloud Foundry.
Who is affected by CVE-2024-37082?
Organizations using Cloud Foundry with route-services enabled in non-default configurations are affected by CVE-2024-37082.
What exploit does CVE-2024-37082 allow?
CVE-2024-37082 allows the crafting of HTTP requests that can bypass mTLS authentication to Cloud Foundry applications.
Is there a workaround for CVE-2024-37082?
As a temporary workaround for CVE-2024-37082, disable route-services or revert to default configurations until a patch is applied.