CVE-2025-31698

Description

A flaw was found in trafficserver. Access control lists (ACLs) configured within ip_allow.config or remap.config incorrectly utilize IP addresses, failing to account for those provided by the PROXY protocol. This can allow an attacker to bypass intended access restrictions by manipulating the source IP address presented via the PROXY protocol. This misconfiguration allows for unintended access based on a non-validated IP address.

Statement

The severity is rated as Moderate because this vulnerability requires a specific, non-default configuration to be exploitable. Apache Traffic Server is primarily available in Red Hat environments through the Extra Packages for Enterprise Linux (EPEL) repository, which is community-supported. The impact is limited to environments where administrators have explicitly enabled and trusted the PROXY protocol for client IP information in their ACL configurations. This reduces the likelihood of broad impact across Red Hat products.

Mitigation

To mitigate this flaw use the new setting (proxy.config.acl.subjects) to choose which IP addresses to use for the ACL if Apache Traffic Server is configured to accept PROXY protocol.

Understanding the Weakness (CWE)

Other

Technical Impact: Varies by Context

Frequently Asked Questions

Want to get errata notifications? Sign up here.