github.com/traefik/traefik/v2 is vulnerable to Incorrect Authorization
82
High Risk
TLS options are mapped to hostnames of a router rule rather than to the router itself, so a TLS option conflict on one host of a multi-host router falls back to default TLS options for every host in that rule. A host that requires client-certificate authentication can stop enforcing mTLS when another host in the same rule conflicts, letting clients without certificates reach the protected backend. The fix adds the core.strictTLSOptions static option, which disables that fallback and marks conflicting routers as errors instead.
You are affected if you are using a version that falls within the vulnerable range and use multi-host routers where one host requires client-certificate authentication while another host can create a TLS option conflict.
github.com/traefik/traefik/v2 is vulnerable to Incorrect Authorization in versions 2.0.0 - 2.11.54.
Upgrade the github.com/traefik/traefik/v2 library to the patch version and enable core.strictTLSOptions; alternatively, ensure all routers serving the same host on an entrypoint reference identical TLS options.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.