S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2020-15129 Scanner

CVE-2020-15129 scanner - Open Redirect vulnerability in Traefik

Est. Time~30 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.1k
Times Used
continuous scan runs
3.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2020-15129
4.7
CVSSmedium
Exploitable remotely over the internet · no authentication required · user interaction needed.

In Traefik before versions 1.7.26, 2.2.8, and 2.3.0-rc3, there exists a potential open redirect vulnerability in Traefik's handling of the "X-Forwarded-Prefix" header. The Traefik API dashboard component doesn't validate that the value of the header "X-Forwarded-Prefix" is a site relative path and will redirect to any header provided URI. Successful exploitation of an open redirect can be used to entice victims to disclose sensitive information. Active Exploitation of this issue is unlikely as it would require active header injection, however the Traefik team addressed this issue nonetheless to prevent abuse in e.g. cache poisoning scenarios.

Attack Vector
Network
Privileges Req.
None
User Interaction
Required
Affected
traefikby containous
< 1.7.26
Updated Aug 21, 2026View on NVD →
Detail

Traefik is an open-source reverse proxy and load balancer that is popularly used in cloud-native applications and microservices. It is designed to provide developers with an easy and configurable way to manage and route traffic across their applications. With its features such as dynamic service discovery, SSL/TLS encryption, and Kubernetes integration, Traefik simplifies the task of operating distributed applications in a containerized environment.

However, like any other software, vulnerabilities may sometimes be detected in Traefik. One such vulnerability is known as CVE-2020-15129. This vulnerability affects versions before 1.7.26, 2.2.8, and 2.3.0-rc3. It is an open redirect vulnerability in Traefik's handling of the "X-Forwarded-Prefix" header. The issue arises when the Traefik API dashboard component fails to validate that the value of the header "X-Forwarded-Prefix" is a site relative path and will therefore redirect to any header provided URI.

If exploited, the vulnerability can be used to entice victims to disclose sensitive information. For instance, an attacker can craft a malicious link with the opening redirect embedded within it and send this link to a victim. Once the victim clicks on the link, they will be redirected to a phishing site or a fake login page where they may unknowingly enter their login credentials which will then be stolen by the attacker.

At s4e.io, we take the security of our clients' digital assets seriously. Thanks to the pro features of our platform, we make it easy to quickly and easily learn about vulnerabilities in your digital assets. Our platform provides continuous monitoring and scanning of your applications and networks, and we notify you immediately if any vulnerabilities are detected. Sign up today to ensure the safety and security of your digital assets.

 

REFERENCES

Solution Advice

To protect against this vulnerability, Traefik users are advised to upgrade to the latest patched version and implement the following precautions:

  • Ensure all running Traefik instances are updated to the latest patched versions.
  • Block all untrusted request headers. In this case, block the "X-Forwarded-Prefix" header from untrusted sources.
  • Implement a web application firewall (WAF) to monitor traffic and detect malicious requests.
  • Train employees on phishing and social engineering attacks, showing them real-life examples so that they can identify and report fraudulent attempts.
  • Regularly perform security assessments on applications and networks to identify vulnerabilities and proactively address them before they can be exploited.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.