Urgent.News

What's breaking now, across thousands of outlets.

Tech

Dot-Form Header Aliases: How Traefik ForwardAuth Identity Spoofing Reached Backends Before 2.11.56

Dot-Form Header Aliases: How Traefik ForwardAuth Identity Spoofing Reached Backends Before 2.11.56 Why this matters to anyone running a proxy in front of an application A common architecture puts a reverse proxy in front of an application and lets the proxy decide who the caller is. The proxy validates a session or a JWT, then writes an identity header such as X-Authenticated-User into the…

Traefik's ForwardAuth middleware has a vulnerability that allows attackers to spoof identities and gain unauthorized access to backend applications, preceding version 2.11.56. This occurs due to a discrepancy in how Traefik and backend runtimes handle HTTP header names. Traefik canonicalizes header names, but many backends, including CGI, WSGI, PHP, and NGINX, fold dots and underscores into underscores, collapsing multiple header names into a single variable.

An attacker can exploit this by sending a request with a low-privileged identity header and an additional header using a dot-form alias. Traefik treats the alias as an unrelated header, while the backend folds both names into one variable. If the alias's order wins, the backend reads the attacker-supplied identity as the authenticated user.

The vulnerability impacts Traefik v1.x, v2.x through v2.11.55, and v3.0.0 through v3.7.11. The patched versions are v2.11.56 and v3.7.12. To mitigate the risk, operators must upgrade to the patched versions and set the aliasHeadersStrategy option to delete or reject in the entry point. Additionally, applications must treat identity headers as untrusted input and reject requests carrying both canonical and folded headers.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

More from Saturday 3 October →