7.5

CVE-2024-28869

Traefik is an HTTP reverse proxy and load balancer. In affected versions sending a GET request to any Traefik endpoint with the "Content-length" request header results in an indefinite hang with the default configuration. This vulnerability can be exploited by attackers to induce a denial of service. This vulnerability has been addressed in version 2.11.2 and 3.0.0-rc5. Users are advised to upgrade. For affected versions, this vulnerability can be mitigated by configuring the readTimeout option.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
TraefikTraefik Version < 2.11.2
TraefikTraefik Version3.0.0 Update-
TraefikTraefik Version3.0.0 Updatebeta1
TraefikTraefik Version3.0.0 Updatebeta2
TraefikTraefik Version3.0.0 Updatebeta3
TraefikTraefik Version3.0.0 Updatebeta4
TraefikTraefik Version3.0.0 Updatebeta5
TraefikTraefik Version3.0.0 Updaterc1
TraefikTraefik Version3.0.0 Updaterc2
TraefikTraefik Version3.0.0 Updaterc3
TraefikTraefik Version3.0.0 Updaterc4
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.75% 0.724
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
security-advisories@github.com 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE-755 Improper Handling of Exceptional Conditions

The product does not handle or incorrectly handles an exceptional condition.