CVE-2024-49214: Medium severity HAProxy HAProxy vulnerability
QUIC in HAProxy 3.1.x before 3.1-dev7, 3.0.x before 3.0.5, and 2.9.x before 2.9.11 allows opening a 0-RTT session with a spoofed IP address. This can bypass the IP allow/block list functionality.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.4.24-1
Event History
Frequently Asked Questions
What is the severity of CVE-2024-49214?
CVE-2024-49214 is considered a significant vulnerability due to its potential to bypass IP allow/block list functionalities.
How do I fix CVE-2024-49214?
To fix CVE-2024-49214, upgrade HAProxy to version 3.1-dev7 or later, 3.0.5 or later, or 2.9.11 or later.
What versions of HAProxy are affected by CVE-2024-49214?
CVE-2024-49214 affects HAProxy versions prior to 3.1-dev7, 3.0.5, and 2.9.11.
What type of attack does CVE-2024-49214 allow?
CVE-2024-49214 allows an attacker to open a 0-RTT session with a spoofed IP address.
Can CVE-2024-49214 impact network security?
Yes, CVE-2024-49214 can significantly impact network security by allowing unauthorized access to services that rely on IP filtering.