Traefik (pronounced traffic) is an HTTP reverse proxy and load balancer. There is a vulnerability in Traefik that allows the client to provide the X-Forwarded-Prefix header from an untrusted source. This issue has been addressed in versions 2.11.14 and 3.2.1. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Metrics
Affected Vendors & Products
References
History
Mon, 02 Dec 2024 12:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 29 Nov 2024 18:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Traefik (pronounced traffic) is an HTTP reverse proxy and load balancer. There is a vulnerability in Traefik that allows the client to provide the X-Forwarded-Prefix header from an untrusted source. This issue has been addressed in versions 2.11.14 and 3.2.1. Users are advised to upgrade. There are no known workarounds for this vulnerability. | |
Title | X-Forwarded-Prefix Header still allows for Open Redirect in traefik | |
Weaknesses | CWE-601 | |
References |
| |
Metrics |
cvssV4_0
|
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2024-11-29T18:15:34.123Z
Updated: 2024-12-02T11:19:36.740Z
Reserved: 2024-11-04T17:46:16.778Z
Link: CVE-2024-52003
Vulnrichment
Updated: 2024-12-02T11:17:21.860Z
NVD
Status : Received
Published: 2024-11-29T19:15:08.170
Modified: 2024-11-29T19:15:08.170
Link: CVE-2024-52003
Redhat
No data.