Traefik
cpe:2.3:a:traefik:traefik:*:*:*:*:*:*:*
- <= v2.11.31
- <= v3.6.2
A vulnerability exists in Traefik versions prior to 2.11.32 and 3.6.2, allowing requests with URL-encoded restricted characters to bypass path normalization. This issue can lead to path-based routing vulnerabilities, where requests skip the intended middleware and reach unintended backends. For example, a request to an admin path could bypass security controls and access a backend service directly. This vulnerability is fixed in Traefik versions 2.11.32 and 3.6.4.
Exploitation of this vulnerability can bypass access-control middleware, allowing unauthorized access to backend services.
Users can upgrade to Traefik versions 2.11.32 or 3.6.4 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.