PT-2020-20582 · Containous+1 · Traefikee+2

Published

2020-03-16

·

Updated

2024-08-21

·

CVE-2020-9321

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Traefik versions 2.0.0 through 2.1.3 TraefikEE version 2.0.0
Description The issue is related to improper certificate handling. Specifically, the configurationwatcher.go file in Traefik mishandles the purging of certificate contents from providers before logging.
Recommendations For Traefik versions 2.0.0 through 2.1.3, update to version 2.1.4 or later to resolve the issue. For TraefikEE version 2.0.0, update to a version that includes the fix for this issue, as the specific fixed version for TraefikEE is not provided.

Fix

Improper Certificate Validation

Information Disclosure

Weakness Enumeration

Related Identifiers

ALT-PU-2020-2498
ALT-PU-2020-3367
ALT-PU-2022-1253
CVE-2020-9321
GHSA-7H6J-2268-FHCM
GO-2022-0808

Affected Products

Alt Linux
Traefik
Traefikee