Containous Traefik 1.6.x before 1.6.6, when --api is used, exposes the configuration and secret if authentication is missing and the API's port is publicly reachable.
References
Link | Resource |
---|---|
https://github.com/containous/traefik/releases/tag/v1.6.6 | Release Notes |
https://github.com/containous/traefik/pull/3790/commits/368bd170913078732bde58160f92f202f370278b | Third Party Advisory |
https://github.com/containous/traefik/pull/3790/commits/113250ce5735d554c502ca16fb03bb9119ca79f1 | Third Party Advisory |
https://github.com/containous/traefik/pull/3790 | Third Party Advisory |
Configurations
Information
Published : 2018-08-20 18:29
Updated : 2021-07-28 08:04
NVD link : CVE-2018-15598
Mitre link : CVE-2018-15598
JSON object : View
CWE
CWE-287
Improper Authentication
Products Affected
traefik
- traefik