VDB
Sign up
MEDIUM6.1

GHSA-6qq8-5wq3-86rp

Traefik vulnerable to Open Redirect via handling of X-Forwarded-Prefix header

Quick fix

GHSA-6qq8-5wq3-86rp — github.com/traefik/traefik: upgrade to the fixed version with the command below.

go get github.com/traefik/traefik@v1.7.26

Details

## Summary

There exists a potential open redirect vulnerability in Traefik's handling of the `X-Forwarded-Prefix` header. Active Exploitation of this issue is unlikely as it would require active header injection, however the Traefik team addressed this issue nonetheless to prevent abuse in e.g. cache poisoning scenarios.

## Details

The Traefik API dashboard component doesn't validate that the value of the header `X-Forwarded-Prefix` is a site relative path and will redirect to any header provided URI.

e.g.

``` $ curl --header 'Host:traefik.localhost' --header 'X-Forwarded-Prefix:https://example.org' 'http://localhost:8081' <a href="https://example.org/dashboard/">Found</a>.` ```

### Impact A successful exploitation of an open redirect can be used to entice victims to disclose sensitive information.

### Workarounds

By using the `headers` middleware, the request header `X-Forwarded-Prefix` value can be overridden by the value `.` (dot)

- https://docs.traefik.io/v2.2/middlewares/headers/#customrequestheaders - https://docs.traefik.io/v1.7/basics/#custom-headers

### For more information

If you have any questions or comments about this advisory, open an issue in [Traefik](https://github.com/containous/traefik/issues).

## Credit

This issue was found by the GitHub Application Security Team and reported on behalf of the GHAS by the GitHub Security Lab Team.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/traefik/traefik
Introduced in: 1.5.0-rc5Fixed in: 1.7.26
Fixgo get github.com/traefik/traefik@v1.7.26
Go/github.com/traefik/traefik/v2
Introduced in: 0Fixed in: 2.3.0-rc6
Fixgo get github.com/traefik/traefik/v2@v2.3.0-rc6
Go/github.com/containous/traefik
Introduced in: 1.5.0-rc5Fixed in: 1.7.26
Fixgo get github.com/containous/traefik@v1.7.26
Go/github.com/containous/traefik/v2
Introduced in: 0Fixed in: 2.2.8
Fixgo get github.com/containous/traefik/v2@v2.2.8
Go/github.com/traefik/traefik/v2
Introduced in: 2.3.0-rc1Fixed in: 2.3.0-rc6
Fixgo get github.com/traefik/traefik/v2@v2.3.0-rc6
Go/github.com/containous/traefik/v2
Introduced in: 2.3.0-rc1Fixed in: 2.3.0-rc3
Fixgo get github.com/containous/traefik/v2@v2.3.0-rc3
Go/github.com/traefik/traefik/api
Introduced in: 1.5.0-rc5Fixed in: 1.7.26
Fixgo get github.com/traefik/traefik/api@v1.7.26
Go/github.com/traefik/traefik/v2/pkg/api
Introduced in: 0Fixed in: 2.3.0-rc6
Fixgo get github.com/traefik/traefik/v2/pkg/api@v2.3.0-rc6
Go/github.com/traefik/traefik/v2/pkg/api
Introduced in: 2.3.0-rc1Fixed in: 2.3.0-rc6
Fixgo get github.com/traefik/traefik/v2/pkg/api@v2.3.0-rc6
Go/github.com/containous/traefik/api
Introduced in: 1.5.0-rc5Fixed in: 1.7.26
Fixgo get github.com/containous/traefik/api@v1.7.26
Go/github.com/containous/traefik/v2/pkg/api
Introduced in: 0Fixed in: 2.2.8
Fixgo get github.com/containous/traefik/v2/pkg/api@v2.2.8
Go/github.com/containous/traefik/v2/pkg/api
Introduced in: 2.3.0-rc1Fixed in: 2.3.0-rc3
Fixgo get github.com/containous/traefik/v2/pkg/api@v2.3.0-rc3

References