7.5

CVE-2023-29013

HTTP header parsing could cause a deny of service

Traefik (pronounced traffic) is a modern HTTP reverse proxy and load balancer for deploying microservices. There is a vulnerability in Go when parsing the HTTP headers, which impacts Traefik. HTTP header parsing could allocate substantially more memory than required to hold the parsed headers. This behavior could be exploited to cause a denial of service. This issue has been patched in versions 2.9.10 and 2.10.0-rc2.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Traefik ≫ Traefik Version < 2.9.10
Traefik ≫ Traefik Version 2.10.0 Update rc1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.09% 0.609
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
security-advisories@github.com 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE-400 Uncontrolled Resource Consumption

The product does not properly control the allocation and maintenance of a limited resource.

https://github.com/traefik/traefik/commit/4ed3964b3586565519249bbdc55eb1b961c08c49
Patch
https://github.com/traefik/traefik/releases/tag/v2.10.0-rc2
Release Notes
https://github.com/traefik/traefik/releases/tag/v2.9.10
Release Notes
https://github.com/traefik/traefik/security/advisories/GHSA-7hj9-rv74-5g92
Vendor Advisory
https://security.netapp.com/advisory/ntap-20230517-0008/
Third Party Advisory