CyberzSOC

Publication detail
← Back to advisories & guidance

2024-102: Traefik Critical Vulnerability ↗ source

September 24, 2024 CERT-EU Advisory

Summary

This vulnerability could allow an attacker to execute arbitrary commands via crafted HTTP requests, posing a significant risk to exposed services [1,2]. Immediate updates are recommended for all affected installations. The vulnerability CVE-2024-45410 has a CVSS score of 9.8 out of 10. It allows remote code execution due to improper validation of input. The vulnerability arises from Traefik’s handling of HTTP headers which are added during request processing.

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2024-45410 9.8 Critical traefik traefik Traefik is a golang, Cloud Native Application Proxy. When a HTTP request is processed by Traefik, certain HTTP headers such as X-Forwarded-Host or X-…

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

No KEV-catalogued vendors are named in this publication.