Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-3477 | Traefik (pronounced traffic) is an HTTP reverse proxy and load balancer. There is a vulnerability in Traefik that allows the client to provide the X-Forwarded-Prefix header from an untrusted source. This issue has been addressed in versions 2.11.14 and 3.2.1. Users are advised to upgrade. There are no known workarounds for this vulnerability. |
Github GHSA |
GHSA-h924-8g65-j9wg | Traefik's X-Forwarded-Prefix Header still allows for Open Redirect |
Tue, 25 Nov 2025 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:traefik:traefik:*:*:*:*:*:*:*:* | |
| Metrics |
cvssV3_1
|
Mon, 02 Dec 2024 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 29 Nov 2024 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Traefik (pronounced traffic) is an HTTP reverse proxy and load balancer. There is a vulnerability in Traefik that allows the client to provide the X-Forwarded-Prefix header from an untrusted source. This issue has been addressed in versions 2.11.14 and 3.2.1. Users are advised to upgrade. There are no known workarounds for this vulnerability. | |
| Title | X-Forwarded-Prefix Header still allows for Open Redirect in traefik | |
| Weaknesses | CWE-601 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-12-02T11:19:36.740Z
Reserved: 2024-11-04T17:46:16.778Z
Link: CVE-2024-52003
Updated: 2024-12-02T11:17:21.860Z
Status : Analyzed
Published: 2024-11-29T19:15:08.170
Modified: 2025-11-25T13:48:57.257
Link: CVE-2024-52003
No data.
OpenCVE Enrichment
Updated: 2025-07-12T23:05:46Z
EUVD
Github GHSA