Логотип exploitDog
bind:CVE-2020-15129
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-15129

Количество 3

Количество 3

nvd логотип

CVE-2020-15129

больше 5 лет назад

In Traefik before versions 1.7.26, 2.2.8, and 2.3.0-rc3, there exists a potential open redirect vulnerability in Traefik's handling of the "X-Forwarded-Prefix" header. The Traefik API dashboard component doesn't validate that the value of the header "X-Forwarded-Prefix" is a site relative path and will redirect to any header provided URI. Successful exploitation of an open redirect can be used to entice victims to disclose sensitive information. Active Exploitation of this issue is unlikely as it would require active header injection, however the Traefik team addressed this issue nonetheless to prevent abuse in e.g. cache poisoning scenarios.

CVSS3: 6.1
EPSS: Высокий
debian логотип

CVE-2020-15129

больше 5 лет назад

In Traefik before versions 1.7.26, 2.2.8, and 2.3.0-rc3, there exists ...

CVSS3: 6.1
EPSS: Высокий
github логотип

GHSA-6qq8-5wq3-86rp

почти 4 года назад

Traefik vulnerable to Open Redirect via handling of X-Forwarded-Prefix header

CVSS3: 6.1
EPSS: Высокий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2020-15129

In Traefik before versions 1.7.26, 2.2.8, and 2.3.0-rc3, there exists a potential open redirect vulnerability in Traefik's handling of the "X-Forwarded-Prefix" header. The Traefik API dashboard component doesn't validate that the value of the header "X-Forwarded-Prefix" is a site relative path and will redirect to any header provided URI. Successful exploitation of an open redirect can be used to entice victims to disclose sensitive information. Active Exploitation of this issue is unlikely as it would require active header injection, however the Traefik team addressed this issue nonetheless to prevent abuse in e.g. cache poisoning scenarios.

CVSS3: 6.1
77%
Высокий
больше 5 лет назад
debian логотип
CVE-2020-15129

In Traefik before versions 1.7.26, 2.2.8, and 2.3.0-rc3, there exists ...

CVSS3: 6.1
77%
Высокий
больше 5 лет назад
github логотип
GHSA-6qq8-5wq3-86rp

Traefik vulnerable to Open Redirect via handling of X-Forwarded-Prefix header

CVSS3: 6.1
77%
Высокий
почти 4 года назад

Уязвимостей на страницу