6.5
CVSS V3
Traefik routes exposed with an empty TLSOption
There is a potential vulnerability in Traefik managing the TLS connections.
A router configured with a not well-formatted TLSOption is exposed with an empty TLSOption.
For instance, a route secured using an mTLS connection set with a wrong CA file is exposed without verifying the client certificates.
https://github.com/traefik/traefik/releases/tag/v2.9.6
Check the logs to detect the following error messages and fix your TLS options:
If you have any questions or comments about this advisory, please open an issue.