REDHAT-BUG-2464235: High severity Traefik traefik vulnerability
Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.43, 3.6.14, and 3.7.0-rc.2, there is an authentication bypass vulnerability in Traefik's ForwardAuth middleware when trustForwardHeader=false is configured and Traefik is deployed behind a trusted upstream proxy. This issue has been patched in versions 2.11.43, 3.6.14, and 3.7.0-rc.2.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
traefikto a version that resolves this vulnerability.Fixed in 2.11.43 - Upgrade
Upgrade
traefikto a version that resolves this vulnerability.Fixed in 3.6.14 - Upgrade
Upgrade
traefikto a version that resolves this vulnerability.Fixed in 3.7.0-rc.2
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2464235?
The severity of REDHAT-BUG-2464235 is classified as high with a score of 7.
How do I fix REDHAT-BUG-2464235?
To fix REDHAT-BUG-2464235, upgrade to versions 2.11.43, 3.6.14, or 3.7.0-rc.2 of Traefik.
What type of vulnerability is REDHAT-BUG-2464235?
REDHAT-BUG-2464235 is an authentication bypass vulnerability affecting Traefik's ForwardAuth middleware.
What conditions lead to REDHAT-BUG-2464235 being exploitable?
REDHAT-BUG-2464235 is exploitable when trustForwardHeader=false is configured and Traefik is deployed behind a trusted upstream proxy.
Which software versions are affected by REDHAT-BUG-2464235?
Versions prior to 2.11.43, 3.6.14, and 3.7.0-rc.2 of Traefik are affected by REDHAT-BUG-2464235.