Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7jmw-8259-q9jx

Опубликовано: 11 июн. 2024
Источник: github
Github: Прошло ревью

Описание

Traefik has unexpected behavior with IPv4-mapped IPv6 addresses

Impact

There is a vulnerability in Go managing various Is methods (IsPrivate, IsLoopback, etc) for IPv4-mapped IPv6 addresses.

They didn't work as expected returning false for addresses which would return true in their traditional IPv4 forms.

References

Patches

Workarounds

No workaround.

For more information

If you have any questions or comments about this advisory, please open an issue.

Пакеты

Наименование

github.com/traefik/traefik/v3

go
Затронутые версииВерсия исправления

>= 3.0.0-beta3, < 3.0.2

3.0.2

Наименование

github.com/traefik/traefik/v2

go
Затронутые версииВерсия исправления

< 2.11.4

2.11.4

Наименование

github.com/traefik/traefik

go
Затронутые версииВерсия исправления

< 2.11.4

2.11.4

Дефекты

CWE-180

Дефекты

CWE-180