GPU VulnDB

Database/Container, Kubernetes & orchestration

Traefik: Traefik-added X-Forwarded-* headers can be spoofed by the client and are trusted by the backend

CVE-2024-45410Container, Kubernetes & orchestrationcurated

Impact

Traefik-added X-Forwarded-* headers can be spoofed by the client and are trusted by the backend; authentication bypass at the application layer

Who can reach it

Unauthenticated network

What to do

Rolling Traefik upgrade; explicitly configure trusted forwarded headers

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.