The HTTP/2 implementation in HAProxy before 2.0.10 mishandles headers, as demonstrated by carriage return (CR, ASCII 0xd), line feed (LF, ASCII 0xa), and the zero character (NUL, ASCII 0x0), aka Intermediary Encapsulation Attacks. Upstream patch: https://git.haproxy.org/?p=haproxy.git;a=commit;h=54f53ef7ce4102be596130b44c768d1818570344 https://git.haproxy.org/?p=haproxy.git;a=commit;h=146f53ae7e97dbfe496d0445c2802dd0a30b0878 https://git.haproxy.org/?p=haproxy-2.0.git;a=commit;h=ac198b92d461515551b95daae20954b3053ce87e
Created haproxy tracking bugs for this issue: Affects: fedora-all [bug 1777585]
Statement: Support for HTTP/2 protocol was added to haproxy in version 1.8, therefore previous versions are not affected by this flaw. The version of haproxy shipped in OpenShift Container Platform 4 contains the vulnerable code, however exploitation requires setting ROUTER_USE_HTTP2 in the OpenShift Ingress Operator, which is not currently possible. The impact of this vulnerability is therefore reduced in OpenShift Container Platform 4 to Low.
Fixes for haproxy 1.8: http://git.haproxy.org/?p=haproxy-1.8.git;a=commitdiff;h=b8d65bb1f52849665ef6f21d90ec5fc3b7c00bc6 http://git.haproxy.org/?p=haproxy-1.8.git;a=commitdiff;h=4b37de078bfa850ea3d08d02e23b912fd5f8c168 Applied in version 1.8.23.
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 3.11 Via RHSA-2020:1287 https://access.redhat.com/errata/RHSA-2020:1287
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2019-19330
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2020:1725 https://access.redhat.com/errata/RHSA-2020:1725
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.4 Via RHSA-2020:1936 https://access.redhat.com/errata/RHSA-2020:1936
This issue has been addressed in the following products: Red Hat Software Collections for Red Hat Enterprise Linux 7 Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS Via RHSA-2020:2265 https://access.redhat.com/errata/RHSA-2020:2265