configurationwatcher.go in Traefik 2.x before 2.1.4 and TraefikEE 2.0.0 mishandles the purging of certificate contents from providers before logging.
References
Link | Resource |
---|---|
https://github.com/containous/traefik/releases/tag/v2.1.4 | Release Notes |
https://github.com/containous/traefik/pull/6281 | Patch Third Party Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2020-03-16 12:15
Updated : 2021-07-27 17:44
NVD link : CVE-2020-9321
Mitre link : CVE-2020-9321
JSON object : View
CWE
CWE-295
Improper Certificate Validation
Products Affected
traefik
- traefik