PT-2024-6568 · Traefik+1 · Traefik+1

Drolmat

·

Published

2024-08-28

·

Updated

2025-10-02

·

CVE-2024-45410

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Traefik versions prior to 2.11.9 Traefik versions prior to 3.1.3
Description: The issue arises from the manipulation of custom HTTP headers added by Traefik, such as X-Forwarded-Host or X-Forwarded-Port, which can be removed or modified by an HTTP client due to the HTTP/1.1 behavior that allows headers to be defined as hop-by-hop via the HTTP Connection header. This can lead to security implications as the application trusts the value of these headers. The attack relies on this HTTP/1.1 behavior.
Recommendations: For Traefik versions prior to 2.11.9, upgrade to version 2.11.9 or later. For Traefik versions prior to 3.1.3, upgrade to version 3.1.3 or later. As a temporary workaround, consider restricting access to the vulnerable X-Forwarded-Host and X-Forwarded-Port headers until a patch is available. Avoid using the Connection header to define hop-by-hop headers in the affected API endpoints until the issue is resolved.

Exploit

Fix

Insufficient Verification of Data Authenticity

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_16880
ALT-PU-2024-16593
ALT-PU-2024-16754
ALT-PU-2025-12511
ALT-PU-2025-7693
BDU:2024-07712
CVE-2024-45410
ECHO-678C-79A3-E71D
GHSA-62C8-MH53-4CQV
GO-2024-3135
OPENSUSE-SU-2024:14365-1
OPENSUSE-SU-2024:14367-1

Affected Products

Alt Linux
Traefik