PT-2020-20582 · Containous+1 · Traefikee+2
Published
2020-03-16
·
Updated
2024-08-21
·
CVE-2020-9321
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Traefik versions 2.0.0 through 2.1.3
TraefikEE version 2.0.0
Description
The issue is related to improper certificate handling. Specifically, the
configurationwatcher.go file in Traefik mishandles the purging of certificate contents from providers before logging.Recommendations
For Traefik versions 2.0.0 through 2.1.3, update to version 2.1.4 or later to resolve the issue.
For TraefikEE version 2.0.0, update to a version that includes the fix for this issue, as the specific fixed version for TraefikEE is not provided.
Fix
Improper Certificate Validation
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Traefik
Traefikee