Описание
Traefik affected by HTTP/2 CONTINUATION flood in net/http
There is a potential vulnerability in Traefik managing HTTP/2 connections.
More details in the CVE-2023-45288.
Patches
- https://github.com/traefik/traefik/releases/tag/v2.11.2
- https://github.com/traefik/traefik/releases/tag/v3.0.0-rc5
Workarounds
No workaround
For more information
If you have any questions or comments about this advisory, please open an issue.
Пакеты
Наименование
github.com/traefik/traefik/v2
go
Затронутые версииВерсия исправления
< 2.11.2
2.11.2
Наименование
github.com/traefik/traefik/v3
go
Затронутые версииВерсия исправления
>= 3.0.0-rc1, < 3.0.0-rc5
3.0.0-rc5