Integer Overflow or Wraparound Affecting haproxy package, versions [2.0.0,2.0.25)[2.2.0,2.2.17)[2.3.0,2.3.14)[2.4.0,2.4.4)


Severity

Recommended
0.0
high
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
2.35% (90th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UNMANAGED-HAPROXY-2317772
  • published14 Dec 2021
  • disclosed8 Sept 2021
  • creditUnknown

Introduced: 8 Sep 2021

CVE-2021-40346  (opens in a new tab)
CWE-190  (opens in a new tab)

How to fix?

Upgrade haproxy to version 2.0.25, 2.2.17, 2.3.14, 2.4.4 or higher.

Overview

Affected versions of this package are vulnerable to Integer Overflow or Wraparound. An integer overflow exists in HAProxy 2.0 through 2.5 in htx_add_header that can be exploited to perform an HTTP request smuggling attack, allowing an attacker to bypass all configured http-request HAProxy ACLs and possibly other ACLs.

CVSS Scores

version 3.1