Описание
Traefik is an open source HTTP reverse proxy and load balancer. From v3.7.0 prior to v3.7.6, Traefik's Kubernetes Gateway API provider may resolve two accepted HTTPRoutes that target the same backend Service:port but configure different backendRef filters to the same child service and apply only one route's filter set to all requests reaching that backend. In Gateway deployments where backendRef filters set security-sensitive headers, such as tenant identity, authorization context, or values the backend trusts, an attacker who can create an accepted HTTPRoute sharing the same backend Service:port may cause their route's filter context to be applied to another route's requests, potentially crossing namespace boundaries when a ReferenceGrant permits cross-namespace targeting. This issue is fixed in version v3.7.6.
A flaw was found in Traefik's Kubernetes Gateway API provider. An attacker capable of creating an accepted HTTPRoute that shares the same backend Service and port could exploit this vulnerability. The system may incorrectly apply the attacker's route filter context to another route's requests, potentially allowing unauthorized access or information disclosure across different namespaces. This could lead to the application of security-sensitive headers from the attacker's route to legitimate requests, bypassing intended security controls.
Отчет
This Moderate flaw in Traefik's Kubernetes Gateway API provider, as deployed in Red Hat OpenShift Dev Spaces, could allow an attacker to apply their route's filter context to other requests. This can lead to unauthorized access or information disclosure across namespace boundaries when backendRef filters are used for security-sensitive headers, as it allows bypassing intended security controls. Exploitation requires the attacker to create an accepted HTTPRoute.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat OpenShift Dev Spaces | devspaces/traefik-rhel9 | Fix deferred |
Показывать по
Ссылки на источники
Дополнительная информация
Статус:
8.5 High
CVSS3
Связанные уязвимости
Traefik is an open source HTTP reverse proxy and load balancer. From v3.7.0 prior to v3.7.6, Traefik's Kubernetes Gateway API provider may resolve two accepted HTTPRoutes that target the same backend Service:port but configure different backendRef filters to the same child service and apply only one route's filter set to all requests reaching that backend. In Gateway deployments where backendRef filters set security-sensitive headers, such as tenant identity, authorization context, or values the backend trusts, an attacker who can create an accepted HTTPRoute sharing the same backend Service:port may cause their route's filter context to be applied to another route's requests, potentially crossing namespace boundaries when a ReferenceGrant permits cross-namespace targeting. This issue is fixed in version v3.7.6.
Traefik is an open source HTTP reverse proxy and load balancer. From v ...
8.5 High
CVSS3