← voltar
CVE-2024-52003

X-Forwarded-Prefix Header still allows for Open Redirect in traefik

CVSS 6.3 MEDIUMEPSS 0.4%CWE-601
Traefik (pronounced traffic) is an HTTP reverse proxy and load balancer. There is a vulnerability in Traefik that allows the client to provide the X-Forwarded-Prefix header from an untrusted source. This issue has been addressed in versions 2.11.14 and 3.2.1. Users are advised to upgrade. There are no known workarounds for this vulnerability.
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
Produtos afetados
traefik · traefik

Quer saber se a sua infraestrutura está exposta a isto?

Falar com a TrueHacking →