PT-2022-16146 · Traefik+1 · Traefik+1

Published

2022-02-16

·

Updated

2026-01-12

·

CVE-2022-23632

CVSS v3.1

7.4

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Traefik versions prior to 2.6.1
Description The issue arises when Traefik, an HTTP reverse proxy and load balancer, skips the router transport layer security (TLS) configuration when the host header is a fully qualified domain name (FQDN). This can lead to the use of a wrong TLS configuration, as the TLS configuration choice may differ from the router choice. When a request is sent using an FQDN handled by a router with a dedicated TLS configuration, the TLS configuration falls back to the default configuration, which may not match the configured one. If CNAME flattening is enabled, the selected TLS configuration is the SNI one, and the routing uses the CNAME value, potentially skipping the expected TLS configuration.
Recommendations For versions prior to 2.6.1, update to version 2.6.1 to resolve the issue. As a temporary workaround for versions prior to 2.6.1, add the FQDN to the host rule. Note that there is no workaround if CNAME flattening is enabled.

Exploit

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2022-2056
ALT-PU-2022-2427
CVE-2022-23632
ECHO-066F-5A18-8F31
GHSA-HRHX-6H34-J5HC
GO-2022-0325

Affected Products

Alt Linux
Traefik