CVE-2024-39321
Traefik vulnerable to bypassing IP allow-lists via HTTP/3 early data requests in QUIC 0-RTT handshakes
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Traefik is an HTTP reverse proxy and load balancer. Versions prior to 2.11.6, 3.0.4, and 3.1.0-rc3 have a vulnerability that allows bypassing IP allow-lists via HTTP/3 early data requests in QUIC 0-RTT handshakes sent with spoofed IP addresses. Versions 2.11.6, 3.0.4, and 3.1.0-rc3 contain a patch for this issue. No known workarounds are available.
Traefik es un proxy inverso HTTP y un equilibrador de carga. Las versiones anteriores a 2.11.6, 3.0.4 y 3.1.0-rc3 tienen una vulnerabilidad que permite eludir las listas de direcciones IP permitidas a través de solicitudes de datos tempranas HTTP/3 en protocolos de enlace QUIC 0-RTT enviados con direcciones IP falsificadas. Las versiones 2.11.6, 3.0.4 y 3.1.0-rc3 contienen un parche para este problema. No hay soluciones conocidas disponibles.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2024-06-21 CVE Reserved
- 2024-07-05 CVE Published
- 2024-07-06 EPSS Updated
- 2024-08-02 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-639: Authorization Bypass Through User-Controlled Key
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
https://github.com/traefik/traefik/releases/tag/v2.11.6 | X_refsource_misc | |
https://github.com/traefik/traefik/releases/tag/v3.0.4 | X_refsource_misc | |
https://github.com/traefik/traefik/releases/tag/v3.1.0-rc3 | X_refsource_misc | |
https://github.com/traefik/traefik/security/advisories/GHSA-gxrv-wf35-62w9 | X_refsource_confirm |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Traefik Search vendor "Traefik" | Traefik Search vendor "Traefik" for product "Traefik" | < 2.11.6 Search vendor "Traefik" for product "Traefik" and version " < 2.11.6" | en |
Affected
| ||||||
Traefik Search vendor "Traefik" | Traefik Search vendor "Traefik" for product "Traefik" | >= 3.0.0 < 3.0.4 Search vendor "Traefik" for product "Traefik" and version " >= 3.0.0 < 3.0.4" | en |
Affected
| ||||||
Traefik Search vendor "Traefik" | Traefik Search vendor "Traefik" for product "Traefik" | 3.1.0 Search vendor "Traefik" for product "Traefik" and version "3.1.0" | en |
Affected
|