REDHAT-BUG-2452289: High severity Traefik traefik vulnerability
Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.42, 3.6.11, and 3.7.0-ea.3, when headerField is configured with a non-canonical HTTP header name (e.g., x-auth-user instead of X-Auth-User), an authenticated attacker can inject their own canonical version of that header to impersonate any identity to the backend. The backend receives two header entries — the attacker-injected canonical one is read first, overriding Traefik's non-canonical write. Versions 2.11.42, 3.6.11, and 3.7.0-ea.3 patch the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.11.42 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 3.6.11 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 3.7.0-ea.3
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2452289?
The severity of REDHAT-BUG-2452289 is high, rated at 7.
How do I fix REDHAT-BUG-2452289?
To fix REDHAT-BUG-2452289, upgrade Traefik to versions 2.11.42, 3.6.11, or 3.7.0-ea.3 or later.
What vulnerability does REDHAT-BUG-2452289 describe?
REDHAT-BUG-2452289 describes a vulnerability that allows an authenticated attacker to inject a canonical version of a non-canonical HTTP header name.
Which versions of Traefik are affected by REDHAT-BUG-2452289?
Traefik versions prior to 2.11.42, 3.6.11, and 3.7.0-ea.3 are affected by REDHAT-BUG-2452289.
What potential impact does REDHAT-BUG-2452289 have?
The potential impact of REDHAT-BUG-2452289 is unauthorized header injection by authenticated attackers.