​
DirectorySecurity Advisories
Sign In
Security Advisories

CGA-wxx9-7c6r-jp6p

Published

Last updated

https://images.chainguard.dev/security/CGA-wxx9-7c6r-jp6p
Package

traefik

Latest Update
Fixed
Fixed Version

2.10.6-r0

Aliases
  • CVE-2023-47124
  • GHSA-8g85-whqh-cr2f

Severity

5.9

Medium

CVSS V3

Summary

Traefik vulnerable to potential DDoS via ACME HTTPChallenge

Description

Impact

There is a potential vulnerability in Traefik managing the ACME HTTP challenge.

When Traefik is configured to use the HTTPChallenge to generate and renew the Let's Encrypt TLS certificates, the delay authorized to solve the challenge (50 seconds) can be exploited by attackers (slowloris attack).

Patches

Workarounds

Replace the HTTPChallenge with the TLSChallenge or the DNSChallenge.

For more information

If you have any questions or comments about this advisory, please open an issue.

References

Updates


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2024 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard Images