GHSA-7v4p-328v-8v5gHighCVSS 7.5
Traefik vulnerable to HTTP/2 request causing denial of service
🔗 CVE IDs covered (1)
📋 Description
Impact
A vulnerability CVE-2023-39325 exists in Go managing HTTP/2 requests, which impacts Traefik. This vulnerability could be exploited to cause a denial of service.
References
Patches
- https://github.com/traefik/traefik/releases/tag/v2.10.5
- https://github.com/traefik/traefik/releases/tag/v3.0.0-beta4
🎯 Affected products2
- go/github.com/traefik/traefik:< 2.10.5
- go/github.com/traefik/traefik:>= 3.0.0-beta1, < 3.0.0-beta4
🔗 References (8)
- https://github.com/traefik/traefik/security/advisories/GHSA-7v4p-328v-8v5g
- https://groups.google.com/g/golang-announce/c/iNNxDTCjZvo/m/UDd7VKQuAAAJ?pli=1
- https://nvd.nist.gov/vuln/detail/CVE-2023-54365
- https://access.redhat.com/security/cve/CVE-2023-54365
- https://bugzilla.redhat.com/show_bug.cgi?id=2491710
- https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-54365.json
- https://www.vulncheck.com/advisories/traefik-denial-of-service-via-http-2-request-handling
- https://github.com/advisories/GHSA-7v4p-328v-8v5g