GHSA-fvhj-4qfh-q2hm

    Dashboard / Vulnerabilities / GHSA-fvhj-4qfh-q2hm

    GHSA-fvhj-4qfh-q2hm

    Published: 5 Dec 2023Last Modified: 7 Aug 2026

    Summary: Traefik incorrectly processes fragment in the URL, leads to Authorization Bypass

    Details: ### Summary When a request is sent to Traefik with a URL fragment, Traefik automatically URL encodes and forwards the fragment to the backend server. This violates the RFC because in the origin-form the URL should only contain the absolute path and the query. When this is combined with another frontend proxy like Nginx, it can be used to bypass frontend proxy URI-based access control restrictions. ### Details For example, we have this Nginx configuration: ``` location /admin { deny all; return 403; } ``` This can be bypassed when the attacker is requesting to /#/../admin This won’t be vulnerable if the backend server follows the RFC and ignores any characters after the fragment. However, if Nginx is chained with another reverse proxy which automatically URL encode the character # (Traefik) the URL will become /%23/../admin And allow the attacker to completely bypass the Access Restriction from the Nginx Front-End proxy. Here is a diagram to summarize the attack: ![image](https://user-images.githubusercontent.com/47447167/278849578-34ca0546-99b4-44c8-8fc8-8e799c1f5069.png) ### PoC ![image (1)](https://user-images.githubusercontent.com/47447167/278849597-280f2e80-f2d7-4dd9-9662-b8f488fd5ff2.png) This is the POC docker I've set up. It contains Nginx, Traefik proxies and a backend server running PHP. https://drive.google.com/file/d/1vLnA0g7N7ZKhLNmHmuJ4JJjV_J2akNMt/view?usp=sharing ### Impact This allows the attacker to completely bypass the Access Restriction from Front-End proxy.

    Affected packages

    Package

    Name: github.com/traefik/traefik/v2

    Purl: pkg:golang/github.com/traefik/traefik/v2

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -2.10.6

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-fvhj-4qfh-q2hm | CVE-DB