Описание
Traefik HTTP/2 connections management could cause a denial of service
Impact
There is a potential vulnerability in Traefik managing HTTP/2 connections. A closing HTTP/2 server connection could hang forever because of a subsequent fatal error. This failure mode could be exploited to cause a denial of service.
Patches
Traefik v2.8.x: https://github.com/traefik/traefik/releases/tag/v2.8.8 Traefik v2.9.x: https://github.com/traefik/traefik/releases/tag/v2.9.0-rc5
Workarounds
No workaround.
For more information
If you have any questions or comments about this advisory, please open an issue.
Пакеты
github.com/traefik/traefik/v2
< 2.8.8
2.8.8
github.com/traefik/traefik/v2
>= 2.9.0-rc1, < 2.9.0-rc5
2.9.0-rc5
Связанные уязвимости
Traefik (pronounced traffic) is a modern HTTP reverse proxy and load balancer that assists in deploying microservices. There is a potential vulnerability in Traefik managing HTTP/2 connections. A closing HTTP/2 server connection could hang forever because of a subsequent fatal error. This failure mode could be exploited to cause a denial of service. There has been a patch released in versions 2.8.8 and 2.9.0-rc5. There are currently no known workarounds.
Traefik (pronounced traffic) is a modern HTTP reverse proxy and load b ...