/
DirectorySecurity Advisories
Sign In
Security Advisories

CVE-2023-47124

Published

Last updated

NVD

https://nvd.nist.gov/vuln/detail/CVE-2023-47124

CGA ID

CGA-w5f8-74cv-xhp5

Severity

5.9

Medium

CVSS V3

Description

Traefik is an open source HTTP reverse proxy and load balancer. When Traefik is configured to use the HTTPChallenge to generate and renew the Let's Encrypt TLS certificates, the delay authorized to solve the challenge (50 seconds) can be exploited by attackers to achieve a slowloris attack. This vulnerability has been patch in version 2.10.6 and 3.0.0-beta5. Users are advised to upgrade. Users unable to upgrade should replace the HTTPChallenge with the TLSChallenge or the DNSChallenge.

References

Affected packages


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2024 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard Images