Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-c6hx-pjc3-7fqr

Опубликовано: 10 окт. 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Traefik HTTP/2 connections management could cause a denial of service

Impact

There is a potential vulnerability in Traefik managing HTTP/2 connections. A closing HTTP/2 server connection could hang forever because of a subsequent fatal error. This failure mode could be exploited to cause a denial of service.

Patches

Traefik v2.8.x: https://github.com/traefik/traefik/releases/tag/v2.8.8 Traefik v2.9.x: https://github.com/traefik/traefik/releases/tag/v2.9.0-rc5

Workarounds

No workaround.

For more information

If you have any questions or comments about this advisory, please open an issue.

Пакеты

Наименование

github.com/traefik/traefik/v2

go
Затронутые версииВерсия исправления

< 2.8.8

2.8.8

Наименование

github.com/traefik/traefik/v2

go
Затронутые версииВерсия исправления

>= 2.9.0-rc1, < 2.9.0-rc5

2.9.0-rc5

EPSS

Процентиль: 64%
0.00476
Низкий

7.5 High

CVSS3

Дефекты

CWE-400
CWE-755

Связанные уязвимости

CVSS3: 7.5
nvd
больше 3 лет назад

Traefik (pronounced traffic) is a modern HTTP reverse proxy and load balancer that assists in deploying microservices. There is a potential vulnerability in Traefik managing HTTP/2 connections. A closing HTTP/2 server connection could hang forever because of a subsequent fatal error. This failure mode could be exploited to cause a denial of service. There has been a patch released in versions 2.8.8 and 2.9.0-rc5. There are currently no known workarounds.

CVSS3: 7.5
debian
больше 3 лет назад

Traefik (pronounced traffic) is a modern HTTP reverse proxy and load b ...

EPSS

Процентиль: 64%
0.00476
Низкий

7.5 High

CVSS3

Дефекты

CWE-400
CWE-755