Traefik
cpe:2.3:a:traefik:traefik:*:*:*:*:*:*:*
- <= v2.11.42
- <= v3.6.13
- <= v3.7.0-rc.1
An authentication bypass vulnerability has been identified in Traefik's ForwardAuth middleware. This issue affects Traefik versions prior to 2.11.43, 3.6.14, and 3.7.0-rc.2. The vulnerability arises when trustForwardHeader is set to false, and Traefik is deployed behind a trusted upstream proxy. In this configuration, while standard X-Forwarded headers are properly managed, the X-Forwarded-Prefix header is not stripped or rebuilt. This oversight allows attackers to spoof prefix values, potentially bypassing authentication and gaining unauthorized access to protected backend routes.
Exploitation of this vulnerability allows for authentication bypass, enabling unauthorized access to protected routes on the backend.
Users can upgrade to Traefik versions 2.11.43, 3.6.14, or 3.7.0-rc.2 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.