漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Traefik before 3.7.7 Namespace Confusion via HTTPRoute ExtensionRef
Vulnerability Description
Traefik versions 3.7.0 through 3.7.6 contain a namespace confusion vulnerability in the Kubernetes Gateway API provider. When resolving HTTPRoute.spec.rules[].backendRefs[].filters[].extensionRef, Traefik used the backend Service namespace instead of the HTTPRoute namespace. A low-privileged route author holding a ReferenceGrant for a cross-namespace Service could therefore bind a Traefik Middleware from the backend namespace without a separate grant for that middleware, potentially injecting trusted reverse-proxy identity headers into downstream requests. The issue is fixed in version 3.7.7.
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N
Vulnerability Type
授权机制不正确
Vulnerability Title
Traefik 授权问题漏洞
Vulnerability Description
Traefik是Traefik公司开源的一款反向代理与负载均衡工具。 Traefik 3.7.0至3.7.6版本存在授权问题漏洞,该漏洞源于Kubernetes Gateway API提供程序中的命名空间混淆问题,解析HTTPRoute.spec.rules[].backendRefs[].filters[].extensionRef时,使用了后端Service命名空间而非HTTPRoute命名空间,可能导致低权限路由作者绑定后端命名空间中的Traefik中间件,从而向下游请求注入可信的反向代理身份标头。
CVSS Information
N/A
Vulnerability Type
N/A