CVE-2019-20894

Severity CVSS v4.0:
Pending analysis
Type:
CWE-295 Improper Certificate Validation
Publication date:
02/07/2020
Last modified:
28/07/2021

Description

Traefik 2.x, in certain configurations, allows HTTPS sessions to proceed without mutual TLS verification in a situation where ERR_BAD_SSL_CLIENT_AUTH_CERT should have occurred.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:traefik:traefik:*:*:*:*:*:*:*:* 2.0.0 (including) 2.0.1 (excluding)


References to Advisories, Solutions, and Tools