PT-2019-12799 · Containous+1 · Traefik+1

Published

2019-05-29

·

Updated

2024-08-20

·

CVE-2019-12452

CVSS v3.1

7.5

High

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Containous Traefik versions 1.7.x through 1.7.11
Description The issue allows remote authenticated users to discover password hashes by reading the Basic HTTP Authentication or Digest HTTP Authentication section, or discover a key by reading the ClientTLS section. These can be found in the JSON response to a "/api" request. This occurs when the --api flag is used and the API is publicly reachable and exposed without sufficient access control, contrary to the API documentation.
Recommendations For Containous Traefik versions 1.7.x through 1.7.11, restrict access to the "/api" endpoint to minimize the risk of exploitation. As a temporary workaround, consider disabling the API or limiting its exposure to prevent unauthorized access until a patch is available. Ensure proper access control is implemented according to the API documentation to prevent public reachability and exposure of sensitive information.

Exploit

Fix

Insufficiently Protected Credentials

Weakness Enumeration

Related Identifiers

ALT-PU-2019-2525
ALT-PU-2019-2564
CVE-2019-12452
GHSA-R3FQ-CMMW-CPMM
GO-2023-1919

Affected Products

Alt Linux
Traefik