Traefik (pronounced traffic) is an HTTP reverse proxy and load balancer. There is a vulnerability in Traefik that allows the client to provide the X-Forwarded-Prefix header from an untrusted source. This issue has been addressed in versions 2.11.14 and 3.2.1. Users are advised to upgrade. There are no known workarounds for this vulnerability.
History

Mon, 02 Dec 2024 12:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 29 Nov 2024 18:30:00 +0000

Type Values Removed Values Added
Description Traefik (pronounced traffic) is an HTTP reverse proxy and load balancer. There is a vulnerability in Traefik that allows the client to provide the X-Forwarded-Prefix header from an untrusted source. This issue has been addressed in versions 2.11.14 and 3.2.1. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Title X-Forwarded-Prefix Header still allows for Open Redirect in traefik
Weaknesses CWE-601
References
Metrics cvssV4_0

{'score': 6.3, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2024-11-29T18:15:34.123Z

Updated: 2024-12-02T11:19:36.740Z

Reserved: 2024-11-04T17:46:16.778Z

Link: CVE-2024-52003

cve-icon Vulnrichment

Updated: 2024-12-02T11:17:21.860Z

cve-icon NVD

Status : Received

Published: 2024-11-29T19:15:08.170

Modified: 2024-11-29T19:15:08.170

Link: CVE-2024-52003

cve-icon Redhat

No data.