Описание
Traefik versions from v3.7.1 fail to enforce crossProviderNamespaces restrictions on the traefik.ingress.kubernetes.io/service.middlewares Service annotation in the Kubernetes Ingress provider. A namespace-limited tenant excluded from the allowlist can attach an operator-owned middleware to its Service, and if that middleware injects backend credentials, recover them at a controlled backend.
A flaw was found in Traefik. The software fails to enforce crossProviderNamespaces restrictions on the traefik.ingress.kubernetes.io/service.middlewares Service annotation within the Kubernetes Ingress provider. This vulnerability allows a namespace-limited tenant, even if excluded from the allowlist, to attach an operator-owned middleware to its Service. If this middleware injects backend credentials, the tenant can then recover these credentials at a controlled backend, leading to information disclosure.
Отчет
A flaw was found in Traefik's Kubernetes Ingress provider (v3.7.1 through v3.7.10) where crossProviderNamespaces isolation is not enforced for the service.middlewares Service annotation. In multi-tenant Kubernetes clusters, an authenticated namespace-restricted tenant excluded from cross-namespace allowlists can attach operator-owned middlewares from external namespaces to their Service. If the attached middleware injects upstream backend credentials, the unauthorized tenant can intercept and recover those credentials at a tenant-controlled backend endpoint.
Меры по смягчению последствий
Restrict user permissions to modify Service annotations using Kubernetes Admission Controllers or Kyverno policies to prevent unauthorized referencing of traefik.ingress.kubernetes.io/service.middlewares. Alternatively, disable cross-provider namespace resolution in the Traefik Ingress provider configuration until patched.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat OpenShift Dev Spaces | devspaces/traefik-rhel9 | Not affected | ||
| Red Hat OpenShift GitOps | openshift-gitops-1/argo-rollouts-rhel8 | Not affected | ||
| Red Hat OpenShift GitOps | openshift-gitops-1/argo-rollouts-rhel9 | Not affected |
Показывать по
Дополнительная информация
Статус:
7.7 High
CVSS3
Связанные уязвимости
Traefik versions from v3.7.1 fail to enforce crossProviderNamespaces restrictions on the traefik.ingress.kubernetes.io/service.middlewares Service annotation in the Kubernetes Ingress provider. A namespace-limited tenant excluded from the allowlist can attach an operator-owned middleware to its Service, and if that middleware injects backend credentials, recover them at a controlled backend.
Traefik versions from v3.7.1 fail to enforce crossProviderNamespaces r ...
Traefik versions from v3.7.1 fail to enforce crossProviderNamespaces restrictions on the traefik.ingress.kubernetes.io/service.middlewares Service annotation in the Kubernetes Ingress provider. A namespace-limited tenant excluded from the allowlist can attach an operator-owned middleware to its Service, and if that middleware injects backend credentials, recover them at a controlled backend.
7.7 High
CVSS3