{
  "entrypoint_kind": "endpoint",
  "entrypoint_detail": "HTTP GET /protected/ on a digestAuth-protected Traefik router (file provider config, entrypoint web :80) with a forged Digest Authorization header for an unknown username",
  "service_started": true,
  "healthcheck_passed": true,
  "target_path_reached": true,
  "runtime_stack": [
    "docker-engine",
    "traefik:v2.11.54 (primary vulnerable target)",
    "traefik:v3.6.11 (v3-line vulnerable)",
    "traefik:v2.11.55 (fixed negative control, contains fix commit 2116686308a2)",
    "traefik:v3.7.11 (first fixed v3 tag)",
    "traefik:v3.6.12 (ticket-claimed fixed v3, empirically still vulnerable)",
    "python:3-alpine (protected backend service)"
  ],
  "target_identity": {
    "repository_url": "https://github.com/traefik/traefik",
    "target_digest": "sha256:f10edd30d17cb177579228c6a4a507214defce6fa87ab4739d6a0c42f2a05162",
    "runtime_digest": "sha256:f10edd30d17cb177579228c6a4a507214defce6fa87ab4739d6a0c42f2a05162",
    "platform": "linux",
    "architecture": "amd64"
  },
  "proof_artifacts": [
    "repro/artifacts/http/claimed_fixed_v3_vv3.6.12_attempt1.json",
    "repro/artifacts/http/claimed_fixed_v3_vv3.6.12_attempt1.txt",
    "repro/artifacts/http/claimed_fixed_v3_vv3.6.12_attempt2.json",
    "repro/artifacts/http/claimed_fixed_v3_vv3.6.12_attempt2.txt",
    "repro/artifacts/http/fixed_primary_vv2.11.55_attempt1.json",
    "repro/artifacts/http/fixed_primary_vv2.11.55_attempt1.txt",
    "repro/artifacts/http/fixed_primary_vv2.11.55_attempt2.json",
    "repro/artifacts/http/fixed_primary_vv2.11.55_attempt2.txt",
    "repro/artifacts/http/fixed_v3_control_vv3.7.11_attempt1.json",
    "repro/artifacts/http/fixed_v3_control_vv3.7.11_attempt1.txt",
    "repro/artifacts/http/fixed_v3_control_vv3.7.11_attempt2.json",
    "repro/artifacts/http/fixed_v3_control_vv3.7.11_attempt2.txt",
    "repro/artifacts/http/vuln_primary_vv2.11.54_attempt1.json",
    "repro/artifacts/http/vuln_primary_vv2.11.54_attempt1.txt",
    "repro/artifacts/http/vuln_primary_vv2.11.54_attempt2.json",
    "repro/artifacts/http/vuln_primary_vv2.11.54_attempt2.txt",
    "repro/artifacts/http/vuln_v3_vv3.6.11_attempt1.json",
    "repro/artifacts/http/vuln_v3_vv3.6.11_attempt1.txt",
    "repro/artifacts/http/vuln_v3_vv3.6.11_attempt2.json",
    "repro/artifacts/http/vuln_v3_vv3.6.11_attempt2.txt",
    "repro/exploit_results.json",
    "logs/git_source_verification.log"
  ],
  "artifact_sha256": {
    "repro/artifacts/http/claimed_fixed_v3_vv3.6.12_attempt1.json": "23ecb3ea48fbc95917cd08d720878b95560e42b311a9f19fa00086defd713fbb",
    "repro/artifacts/http/claimed_fixed_v3_vv3.6.12_attempt1.txt": "76480be430b0bb5f03e0bfa98df305ccafc82332e958a11a58bf0aefcc7cf236",
    "repro/artifacts/http/claimed_fixed_v3_vv3.6.12_attempt2.json": "975bbcaf8aed608ecdeab84cd38e929d4e7c6cec88901590420ef1e066a1960f",
    "repro/artifacts/http/claimed_fixed_v3_vv3.6.12_attempt2.txt": "227d8000bbf578c26f626611d661af9e197f13057409a4cc0e28f764a2773976",
    "repro/artifacts/http/fixed_primary_vv2.11.55_attempt1.json": "d47c35fbb0ff4994075c8384d18d837a264d7ef0959bc906272cca6e4306426d",
    "repro/artifacts/http/fixed_primary_vv2.11.55_attempt1.txt": "708cc07b9b4dec79d1d3731dbd8f7fff4db0413a4137bee4f5759255979a815d",
    "repro/artifacts/http/fixed_primary_vv2.11.55_attempt2.json": "b5a54b5d458e6a5e999614bec15e2549d65d6298c1d034b548acaa08e82178d6",
    "repro/artifacts/http/fixed_primary_vv2.11.55_attempt2.txt": "53621bbf36f0d47d5eac48ca3e100f2bc3081e76550ea0253a3edd546fcfdb47",
    "repro/artifacts/http/fixed_v3_control_vv3.7.11_attempt1.json": "7175f1d04508d7b5d8e91af9d3a556872cf0c16a2f64c78afe56dce659aa6469",
    "repro/artifacts/http/fixed_v3_control_vv3.7.11_attempt1.txt": "edc5f820f65efc7e16220c4b578c56eedffd9a52c3a4596467799277bfdb1375",
    "repro/artifacts/http/fixed_v3_control_vv3.7.11_attempt2.json": "d23469521bb8319bda840c641173888c5f5cfac47e692fcc18ed35a107d52211",
    "repro/artifacts/http/fixed_v3_control_vv3.7.11_attempt2.txt": "baa07d5015a654d68e6644ab6453b38c0bc062a9010954eb3ca09b45517ac8a4",
    "repro/artifacts/http/vuln_primary_vv2.11.54_attempt1.json": "dc5beb20b07ebafa40112c7a1145a56173ca7c5c65a7ea27780011c6a45f7e61",
    "repro/artifacts/http/vuln_primary_vv2.11.54_attempt1.txt": "c78a17910700d7392feb1422ab3581353bd5625dabbd5844724f5f7174361fe8",
    "repro/artifacts/http/vuln_primary_vv2.11.54_attempt2.json": "d9268190fcdd6f717cbeb6d67d43eb5a2bf12ed3609fc8ed12ebc4f9ed3e534e",
    "repro/artifacts/http/vuln_primary_vv2.11.54_attempt2.txt": "ab205b3ce562ac9c95ff3d046082bd221df7f11f270095ac810113c845cf286e",
    "repro/artifacts/http/vuln_v3_vv3.6.11_attempt1.json": "07cb9b570be62b15e36cde6fb8471b0c38f2518cc01b38550c430afed7da7361",
    "repro/artifacts/http/vuln_v3_vv3.6.11_attempt1.txt": "878bbd4abb416cd822b3d3cb2e90c81355366743dbfe018524c02b101990c878",
    "repro/artifacts/http/vuln_v3_vv3.6.11_attempt2.json": "d422870ac64e8c07cf2a6c14b7a7a7fd48806450d1d2d487a1e6c328c3d2b429",
    "repro/artifacts/http/vuln_v3_vv3.6.11_attempt2.txt": "50197d887760a93be1058b987273254aa46bdb9008e4e5260dd2333c7e5cc441",
    "repro/exploit_results.json": "bf980fbe19420d35dceef947b96f78299e00b1f101268d6e05949ef76b83f818",
    "logs/git_source_verification.log": "2245f31e1d50f52b05028fa0181ae509e93e511e6656f79b7e05c7fd032b2858"
  },
  "notes": "digestAuth authentication bypass proven through the real Traefik HTTP endpoint. A forged Digest Authorization header for an unknown username with empty HA1 secret reached the protected backend (HTTP 200 PROTECTED-BACKEND-RESOURCE-OK) on traefik:v2.11.54 and traefik:v3.6.11; the fixed images traefik:v2.11.55 and traefik:v3.7.11 reject it with 401. Sanity on every image: valid credentials -> 200, wrong password -> 401, so the middleware and digest math are exercised normally. The ticket claims v3.6.12 is fixed, but the forged digest still succeeds against traefik:v3.6.12 (image digest sha256:171c9c3565b29f6c133f1c1b43c5d4e5853415198e9e1078c001f8702ff66aec); git shows fix commit 2116686308a2518bf1851a39eeec738f1e901195 is absent from all v3.6.x tags and was first released in v2.11.55 (v2 line) and v3.7.11 (v3 line). Tag->commit mapping: v2.11.54=1e8e8c200cce5fbd1fff8579e5e9dc0311a8a54a (vulnerable), v2.11.55=1ac90fccb982f6de40f557493152bdb0c9f0a809 (contains fix), v3.6.11=33219a0af86c41a8db81d37c444f65172bfb3e35 (vulnerable), v3.6.12=b782bd32d444af99d76e5f87970b02a9aa80ba97 (vulnerable), v3.7.11 contains fix. Image repo digests: traefik:v2.11.54=sha256:f10edd30d17cb177579228c6a4a507214defce6fa87ab4739d6a0c42f2a05162, traefik:v2.11.55=sha256:4f87b6b33c1da7a20cf304e8f7340fae1c5da055d3a47095714c39a1ed3d9aa3, traefik:v3.6.11=sha256:acfc80650104f0194a15f73dc1648f517561bc1645391a15705332a064cfc33c, traefik:v3.6.12=sha256:171c9c3565b29f6c133f1c1b43c5d4e5853415198e9e1078c001f8702ff66aec, traefik:v3.7.11=sha256:5203c3f39ca70de6790d964624e042463ffbd57715bc82be155cf224c0dd5144."
}