CVE-2023-47106
When this is combined with another frontend proxy like Nginx, it can be used to bypass frontend proxy URI-based access control restrictions.
Does this matter?
Lower severity and a low EPSS score (0.63%). Track it; it rarely justifies an emergency change on its own.
Description
Traefik is an open source HTTP reverse proxy and load balancer. When a request is sent to Traefik with a URL fragment, Traefik automatically URL encodes and forwards the fragment to the backend server. This violates RFC 7230 because in the origin-form the URL should only contain the absolute path and the query. When this is combined with another frontend proxy like Nginx, it can be used to bypass frontend proxy URI-based access control restrictions. This vulnerability has been addressed in versions 2.10.6 and 3.0.0-beta5. Users are advised to upgrade. There are no known workarounds for this vulnerability.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
- EPSS
- 0.63% probability · 48th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- traefik/traefik
- Source
- security-advisories@github.com
References
- https://datatracker.ietf.org/doc/html/rfc7230#section-5.3.1Not Applicable
- https://github.com/traefik/traefik/releases/tag/v2.10.6Release Notes
- https://github.com/traefik/traefik/releases/tag/v3.0.0-beta5Release Notes
- https://github.com/traefik/traefik/security/advisories/GHSA-fvhj-4qfh-q2hmExploit, Third Party Advisory
- https://datatracker.ietf.org/doc/html/rfc7230#section-5.3.1Not Applicable
- https://github.com/traefik/traefik/releases/tag/v2.10.6Release Notes
- https://github.com/traefik/traefik/releases/tag/v3.0.0-beta5Release Notes
- https://github.com/traefik/traefik/security/advisories/GHSA-fvhj-4qfh-q2hmExploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.