Traefik
cpe:2.3:a:traefik:traefik:*:*:*:*:*:*:*
- <= v2.11.43
- <= v3.6.14
- <= v3.7.0-rc.2
A medium severity information disclosure vulnerability exists in Traefik's errors middleware, prior to versions 2.11.44, 3.6.15, and 3.7.0-rc.3. The vulnerability arises because the middleware forwards the complete header set of the original request, including sensitive information such as Authorization and Cookie headers, to a separate error page service. This occurs when the backend response matches the configured status range. The documentation only mentions that the Host header is forwarded by default, leaving operators unaware that sensitive credentials are being shared across service boundaries. As a result, end-user credentials may be inadvertently exposed to unintended infrastructure.
Exploitation of this vulnerability could lead to unauthorized information disclosure, with sensitive user credentials being exposed to an unintended service or infrastructure component.
Users can upgrade to Traefik versions 2.11.44, 3.6.15, or 3.7.0-rc.3 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.