PT-2019-12799 · Containous+1 · Traefik+1
Published
2019-05-29
·
Updated
2024-08-20
·
CVE-2019-12452
CVSS v3.1
7.5
High
| Vector | AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Containous Traefik versions 1.7.x through 1.7.11
Description
The issue allows remote authenticated users to discover password hashes by reading the Basic HTTP Authentication or Digest HTTP Authentication section, or discover a key by reading the ClientTLS section. These can be found in the JSON response to a "/api" request. This occurs when the --api flag is used and the API is publicly reachable and exposed without sufficient access control, contrary to the API documentation.
Recommendations
For Containous Traefik versions 1.7.x through 1.7.11, restrict access to the "/api" endpoint to minimize the risk of exploitation. As a temporary workaround, consider disabling the API or limiting its exposure to prevent unauthorized access until a patch is available. Ensure proper access control is implemented according to the API documentation to prevent public reachability and exposure of sensitive information.
Exploit
Fix
Insufficiently Protected Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Traefik