StackRadar

CVE-2020-15129

Medium

Advisory

Published 11 Feb 2022In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
6.1
base score, highest
EPSS
0.080
94th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
7
of 17,781 indexed, latest versions
Container images
7
deployed by those charts
Fix available
2 of 2
affected packages

Traefik vulnerable to Open Redirect via handling of X-Forwarded-Prefix header

Carried by container images the latest versions of 7 of 17,781 indexed charts deploy, on 7 images.

Affected packageAffected versionsFixed inImages
github.com/containous/traefik/v2golangv2.1.2, v2.2.32.2.84
github.com/traefik/traefik/v2golangv0.0.0-20230427144611-7805c683e333, v0.0.0-20231128144610-dae0491b612a, v0.0.0-20240212151404-0c8778639a3c2.3.0-rc63
OSV records
GHSA-6qq8-5wq3-86rp

Charts affected

7 by stars
ChartLatestAffected imagesRadar Score
syftopenmined0.9.51 of 6See more

syft openmined 0.9.5

1 of the 6 container images this version deploys carry CVE-2020-15129.

Container imageDigestPackageFixed in
library/traefik:v2.11.00a5157f742d2
github.com/traefik/traefik/v2@v0.0.0-20240212151404-0c8778639a3c
2.3.0-rc6

Open the chart page →

17,245
daskhubdask2024.1.11 of 9See more

daskhub dask 2024.1.1

1 of the 9 container images this version deploys carry CVE-2020-15129.

Container imageDigestPackageFixed in
library/traefik:2.10.61957e3314f43
github.com/traefik/traefik/v2@v0.0.0-20231128144610-dae0491b612a
2.3.0-rc6

Open the chart page →

14,094
traefik-forward-authgeek-cookbookVerified publisher2.2.21 of 1See more

traefik-forward-auth geek-cookbook 2.2.2

1 of the 1 container images this version deploys carry CVE-2020-15129.

Container imageDigestPackageFixed in
thomseddon/traefik-forward-auth:2.2.0e875194d67e2
github.com/containous/traefik/v2@v2.1.2
2.2.8

Open the chart page →

2,234
maeshtraefikOfficialVerified publisher2.1.21 of 7See more

maesh traefik 2.1.2

1 of the 7 container images this version deploys carry CVE-2020-15129.

Container imageDigestPackageFixed in
containous/maesh:v1.3.2587162516502
github.com/containous/traefik/v2@v2.2.3
2.2.8

Open the chart page →

4,136
traefik-forward-authcolearendt0.0.151 of 1See more

traefik-forward-auth colearendt 0.0.15

1 of the 1 container images this version deploys carry CVE-2020-15129.

Container imageDigestPackageFixed in
thomseddon/traefik-forward-auth:269a2c985d2c5
github.com/containous/traefik/v2@v2.1.2
2.2.8

Open the chart page →

2,234
cosmo-traefikcosmoVerified publisher0.9.11 of 2See more

cosmo-traefik cosmo 0.9.1

1 of the 2 container images this version deploys carry CVE-2020-15129.

Container imageDigestPackageFixed in
library/traefik:v2.10.11489caffaedb
github.com/traefik/traefik/v2@v0.0.0-20230427144611-7805c683e333
2.3.0-rc6

Open the chart page →

3,672
traefik-forward-auth-openidnas-helm-chartsVerified publisher1.0.11 of 1See more

traefik-forward-auth-openid nas-helm-charts 1.0.1

1 of the 1 container images this version deploys carry CVE-2020-15129.

Container imageDigestPackageFixed in
thomseddon/traefik-forward-auth:latestb364aa6a4117
github.com/containous/traefik/v2@v2.1.2
2.2.8

Open the chart page →

2,197

Container images carrying it

7 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
containous/maesh:v1.3.2587162516502
github.com/containous/traefik/v2@v2.2.3
2.2.8
1
library/traefik:v2.11.00a5157f742d2
github.com/traefik/traefik/v2@v0.0.0-20240212151404-0c8778639a3c
2.3.0-rc6
1
library/traefik:v2.10.11489caffaedb
github.com/traefik/traefik/v2@v0.0.0-20230427144611-7805c683e333
2.3.0-rc6
1
library/traefik:2.10.61957e3314f43
github.com/traefik/traefik/v2@v0.0.0-20231128144610-dae0491b612a
2.3.0-rc6
1
thomseddon/traefik-forward-auth:269a2c985d2c5
github.com/containous/traefik/v2@v2.1.2
2.2.8
1
thomseddon/traefik-forward-auth:latestb364aa6a4117
github.com/containous/traefik/v2@v2.1.2
2.2.8
1
thomseddon/traefik-forward-auth:2.2.0e875194d67e2
github.com/containous/traefik/v2@v2.1.2
2.2.8
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.