Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h3pc-28cx-rr37

Опубликовано: 04 сент. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 7

Описание

Traefik versions from v3.7.1 fail to enforce crossProviderNamespaces restrictions on the traefik.ingress.kubernetes.io/service.middlewares Service annotation in the Kubernetes Ingress provider. A namespace-limited tenant excluded from the allowlist can attach an operator-owned middleware to its Service, and if that middleware injects backend credentials, recover them at a controlled backend.

Traefik versions from v3.7.1 fail to enforce crossProviderNamespaces restrictions on the traefik.ingress.kubernetes.io/service.middlewares Service annotation in the Kubernetes Ingress provider. A namespace-limited tenant excluded from the allowlist can attach an operator-owned middleware to its Service, and if that middleware injects backend credentials, recover them at a controlled backend.

EPSS

Процентиль: 12%
0.00215
Низкий

7 High

CVSS4

Дефекты

CWE-639

Связанные уязвимости

CVSS3: 7.7
redhat
12 дней назад

Traefik versions from v3.7.1 fail to enforce crossProviderNamespaces restrictions on the traefik.ingress.kubernetes.io/service.middlewares Service annotation in the Kubernetes Ingress provider. A namespace-limited tenant excluded from the allowlist can attach an operator-owned middleware to its Service, and if that middleware injects backend credentials, recover them at a controlled backend.

nvd
12 дней назад

Traefik versions from v3.7.1 fail to enforce crossProviderNamespaces restrictions on the traefik.ingress.kubernetes.io/service.middlewares Service annotation in the Kubernetes Ingress provider. A namespace-limited tenant excluded from the allowlist can attach an operator-owned middleware to its Service, and if that middleware injects backend credentials, recover them at a controlled backend.

debian
12 дней назад

Traefik versions from v3.7.1 fail to enforce crossProviderNamespaces r ...

EPSS

Процентиль: 12%
0.00215
Низкий

7 High

CVSS4

Дефекты

CWE-639