haproxy: Denial of service via set-cookie2 header
Published Mar 2, 2022
7.5
HIGHCVSS 3.1
EPSS 16.56%
Description
A flaw was found in the way HAProxy processed HTTP responses containing the "Set-Cookie2" header. This flaw could allow an attacker to send crafted HTTP response packets which lead to an infinite loop, eventually resulting in a denial of service condition. The highest threat from this vulnerability is availability.
Affected products
- Vendor n/a Product HAProxy Defaultn/a
- Version 2.5.1StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | HAProxy | n/a |
|
Configuration 1
Configuration 2
- 4.0
- n/a
- 7.0
- 8.0
Configuration 3
- 11.0
No data.
Red Hat OpenShift Container Platform 4.6
haproxy-0:2.0.16-3.el7
Fixed · RHSA-2022:1620
Red Hat OpenShift Container Platform 4.7
haproxy-0:2.0.19-3.el7
Fixed · RHSA-2022:1336
Red Hat OpenShift Container Platform 4.8
haproxy-0:2.2.13-3.el8
Fixed · RHSA-2022:1153
Red Hat OpenShift Container Platform 4.9
haproxy-0:2.2.15-4.el8
Fixed · RHSA-2022:1021
Red Hat Enterprise Linux 6
haproxy
Not affected
Red Hat Enterprise Linux 7
haproxy
Not affected
Red Hat Enterprise Linux 8
haproxy
Not affected
Red Hat Enterprise Linux 9
haproxy
Not affected
Red Hat OpenShift Container Platform 3.11
haproxy
Not affected
Red Hat Software Collections
rh-haproxy18-haproxy
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat OpenShift Container Platform 4.6 | haproxy-0:2.0.16-3.el7 | Fixed | RHSA-2022:1620 |
| Red Hat OpenShift Container Platform 4.7 | haproxy-0:2.0.19-3.el7 | Fixed | RHSA-2022:1336 |
| Red Hat OpenShift Container Platform 4.8 | haproxy-0:2.2.13-3.el8 | Fixed | RHSA-2022:1153 |
| Red Hat OpenShift Container Platform 4.9 | haproxy-0:2.2.15-4.el8 | Fixed | RHSA-2022:1021 |
| Red Hat Enterprise Linux 6 | haproxy | Not affected | n/a |
| Red Hat Enterprise Linux 7 | haproxy | Not affected | n/a |
| Red Hat Enterprise Linux 8 | haproxy | Not affected | n/a |
| Red Hat Enterprise Linux 9 | haproxy | Not affected | n/a |
| Red Hat OpenShift Container Platform 3.11 | haproxy | Not affected | n/a |
| Red Hat Software Collections | rh-haproxy18-haproxy | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue was introduced in HAProxy 1.9 with the Native HTTP Representation (HTX). Red Hat Enterprise Linux 6, 7, 8 and Red Hat Software Collections are not affected by this flaw, as they ship older versions of `haproxy` which do not include support for HTX.
References (10)
- https://access.redhat.com/security/cve/CVE-2022-0711 Vendor Advisory
- https://access.redhat.com/security/cve/cve-2022-0711 x_refsource_MISCThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2053666 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-15786 Advisory
- https://github.com/haproxy/haproxy/commit/bfb15ab34ead85f64cd6da0e9fb418c9cd14cee8 x_refsource_MISCPatchThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-0711
- https://www.cve.org/CVERecord?id=CVE-2022-0711
- https://www.debian.org/security/2022/dsa-5102 vendor-advisoryx_refsource_DEBIANThird Party Advisory
- https://www.mail-archive.com/haproxy%40formilux.org/msg41833.html x_refsource_MISC
- https://www.mail-archive.com/haproxy@formilux.org/msg41833.html
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2022-0711 | Vendor Advisory | |
| https://access.redhat.com/security/cve/cve-2022-0711 | x_refsource_MISCThird Party Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2053666 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-15786 | Advisory | |
| https://github.com/haproxy/haproxy/commit/bfb15ab34ead85f64cd6da0e9fb418c9cd14cee8 | x_refsource_MISCPatchThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2022-0711 | ||
| https://www.cve.org/CVERecord?id=CVE-2022-0711 | ||
| https://www.debian.org/security/2022/dsa-5102 | vendor-advisoryx_refsource_DEBIANThird Party Advisory | |
| https://www.mail-archive.com/haproxy%40formilux.org/msg41833.html | x_refsource_MISC | |
| https://www.mail-archive.com/haproxy@formilux.org/msg41833.html |
Change history (0)
No recorded changes yet.