PT-2020-14209 · Containous+1 · Traefik+1
Published
2019-10-03
·
Updated
2022-02-11
·
CVE-2020-15129
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:H/PR:N/UI:R/S:C/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Traefik versions prior to 1.7.26
Traefik versions prior to 2.2.8
Traefik versions prior to 2.3.0-rc3
Description
The issue concerns Traefik's handling of the
X-Forwarded-Prefix header, where the Traefik API dashboard component does not validate if the header value is a site relative path, allowing redirects to any provided URI. This could be exploited to entice victims into disclosing sensitive information. Active exploitation is considered unlikely due to the requirement for active header injection, but the issue was addressed to prevent potential abuse, such as cache poisoning scenarios.Recommendations
For versions prior to 1.7.26, update to version 1.7.26 or later.
For versions prior to 2.2.8, update to version 2.2.8 or later.
For versions prior to 2.3.0-rc3, update to version 2.3.0-rc3 or later.
As a temporary workaround, consider using the
headers middleware to override the X-Forwarded-Prefix header value with a dot (.) to prevent malicious redirects.Fix
Open Redirect
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Traefik