Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Traefik before 3.7.7 Namespace Confusion via HTTPRoute ExtensionRef
Vulnerability Description
Traefik versions 3.7.0 through 3.7.6 contain a namespace confusion vulnerability in the Kubernetes Gateway API provider. When resolving HTTPRoute.spec.rules[].backendRefs[].filters[].extensionRef, Traefik used the backend Service namespace instead of the HTTPRoute namespace. A low-privileged route author holding a ReferenceGrant for a cross-namespace Service could therefore bind a Traefik Middleware from the backend namespace without a separate grant for that middleware, potentially injecting trusted reverse-proxy identity headers into downstream requests. The issue is fixed in version 3.7.7.
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N
Vulnerability Type
授权机制不正确
Vulnerability Title
Traefik 授权问题漏洞
Vulnerability Description
Traefik是Traefik公司开源的一款反向代理与负载均衡工具。 Traefik 3.7.0至3.7.6版本存在授权问题漏洞,该漏洞源于Kubernetes Gateway API提供程序中的命名空间混淆问题,解析HTTPRoute.spec.rules[].backendRefs[].filters[].extensionRef时,使用了后端Service命名空间而非HTTPRoute命名空间,可能导致低权限路由作者绑定后端命名空间中的Traefik中间件,从而向下游请求注入可信的反向代理身份标头。
CVSS Information
N/A
Vulnerability Type
N/A