CVE-2023-29013
There is a vulnerability in Go when parsing the HTTP headers, which impacts Traefik.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.08%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Traefik (pronounced traffic) is a modern HTTP reverse proxy and load balancer for deploying microservices. There is a vulnerability in Go when parsing the HTTP headers, which impacts Traefik. HTTP header parsing could allocate substantially more memory than required to hold the parsed headers. This behavior could be exploited to cause a denial of service. This issue has been patched in versions 2.9.10 and 2.10.0-rc2.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 1.08% probability · 63th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-400
- Affected
- traefik/traefik
- Source
- security-advisories@github.com
References
- https://github.com/traefik/traefik/commit/4ed3964b3586565519249bbdc55eb1b961c08c49Patch
- https://github.com/traefik/traefik/releases/tag/v2.10.0-rc2Release Notes
- https://github.com/traefik/traefik/releases/tag/v2.9.10Release Notes
- https://github.com/traefik/traefik/security/advisories/GHSA-7hj9-rv74-5g92Vendor Advisory
- https://security.netapp.com/advisory/ntap-20230517-0008/Third Party Advisory
- https://github.com/traefik/traefik/commit/4ed3964b3586565519249bbdc55eb1b961c08c49Patch
- https://github.com/traefik/traefik/releases/tag/v2.10.0-rc2Release Notes
- https://github.com/traefik/traefik/releases/tag/v2.9.10Release Notes
- https://github.com/traefik/traefik/security/advisories/GHSA-7hj9-rv74-5g92Vendor Advisory
- https://security.netapp.com/advisory/ntap-20230517-0008/Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.