CVE-2022-39271
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
11/10/2022
Last modified:
14/07/2023
Description
Traefik (pronounced traffic) is a modern HTTP reverse proxy and load balancer that assists in deploying microservices. There is a potential vulnerability in Traefik managing HTTP/2 connections. A closing HTTP/2 server connection could hang forever because of a subsequent fatal error. This failure mode could be exploited to cause a denial of service. There has been a patch released in versions 2.8.8 and 2.9.0-rc5. There are currently no known workarounds.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:traefik:traefik:*:*:*:*:*:*:*:* | 2.8.8 (excluding) | |
cpe:2.3:a:traefik:traefik:2.9.0:rc1:*:*:*:*:*:* | ||
cpe:2.3:a:traefik:traefik:2.9.0:rc2:*:*:*:*:*:* | ||
cpe:2.3:a:traefik:traefik:2.9.0:rc3:*:*:*:*:*:* | ||
cpe:2.3:a:traefik:traefik:2.9.0:rc4:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page