configurationwatcher.go in Traefik 2.x before 2.1.4 and TraefikEE 2.0.0 mishandles the purging of certificate contents from providers before logging.
References
Link | Resource |
---|---|
https://github.com/containous/traefik/pull/6281 | Patch Third Party Advisory |
https://github.com/containous/traefik/releases/tag/v2.1.4 | Release Notes |
https://github.com/containous/traefik/pull/6281 | Patch Third Party Advisory |
https://github.com/containous/traefik/releases/tag/v2.1.4 | Release Notes |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 05:40
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/containous/traefik/pull/6281 - Patch, Third Party Advisory | |
References | () https://github.com/containous/traefik/releases/tag/v2.1.4 - Release Notes |
Information
Published : 2020-03-16 19:15
Updated : 2024-11-21 05:40
NVD link : CVE-2020-9321
Mitre link : CVE-2020-9321
CVE.ORG link : CVE-2020-9321
JSON object : View
Products Affected
traefik
- traefik
CWE
CWE-295
Improper Certificate Validation