Описание
Traefik is an open-source edge router that makes publishing services a fun and easy experience. Prior to 2.11.54, 3.6.25, and 3.7.10, cross-namespace @kubernetescrd references are not rejected for TraefikService backend references resolved by the service resolver. A tenant confined by RBAC to a single namespace can therefore bind its own router to a TraefikService owned by another namespace and expose or reroute that namespace's backend, defeating the namespace isolation allowCrossNamespace=false is meant to enforce. This issue is fixed in version 2.11.54, 3.6.25, 3.7.10.
A flaw was found in Traefik. This flaw allows a tenant, even when restricted by Role-Based Access Control (RBAC) to a single namespace, to bypass namespace isolation. By binding their own router to a TraefikService in another namespace, an attacker can expose or reroute that namespace's backend services. This defeats the intended allowCrossNamespace=false enforcement, leading to unauthorized access or manipulation of services across namespaces.
Отчет
A flaw in Traefik's service resolver allows a lower-privileged tenant to reference and bind cross-namespace TraefikService objects via @kubernetescrd, even when allowCrossNamespace=false is configured. By creating a custom router targeting an isolated TraefikService CRD in a separate namespace, an authenticated attacker can bypass namespace isolation controls, intercepting or rerouting backend service traffic across multi-tenant boundaries.
Меры по смягчению последствий
To mitigate this flaw, restrict RBAC permissions to prevent non-administrative users from creating or modifying custom Traefik IngressRoute and TraefikService Custom Resource Definitions (CRDs). Alternatively, segregate sensitive backend workloads into dedicated Traefik ingress controller instances.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat OpenShift Dev Spaces | devspaces/traefik-rhel9 | Affected | ||
| Red Hat OpenShift GitOps | openshift-gitops-1/argo-rollouts-rhel8 | Not affected | ||
| Red Hat OpenShift GitOps | openshift-gitops-1/argo-rollouts-rhel9 | Not affected |
Показывать по
Ссылки на источники
Дополнительная информация
Статус:
8.7 High
CVSS3
Связанные уязвимости
Traefik is an open-source edge router that makes publishing services a fun and easy experience. Prior to 2.11.54, 3.6.25, and 3.7.10, cross-namespace @kubernetescrd references are not rejected for TraefikService backend references resolved by the service resolver. A tenant confined by RBAC to a single namespace can therefore bind its own router to a TraefikService owned by another namespace and expose or reroute that namespace's backend, defeating the namespace isolation allowCrossNamespace=false is meant to enforce. This issue is fixed in version 2.11.54, 3.6.25, 3.7.10.
Traefik is an open-source edge router that makes publishing services a ...
Traefik: `allowCrossNamespace=false` bypass via `@kubernetescrd` TraefikService backendRef
Уязвимость функции nameAndService() файла pkg/provider/kubernetes/crd/kubernetes_http.go провайдера интеграции с Kubernetes CRD обратного прокси сервера Containous Traefik, позволяющая нарущителю получить несанкционированный доступ к защищаемой информации
8.7 High
CVSS3