PT-2019-12799 · Containous+1 · Traefik+1

CVE-2019-12452

·

Publicado

2019-05-29

·

Atualizado

2024-08-20

CVSS v3.1

7.5

Alta

VetorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Containous Traefik versions 1.7.x through 1.7.11
Description The issue allows remote authenticated users to discover password hashes by reading the Basic HTTP Authentication or Digest HTTP Authentication section, or discover a key by reading the ClientTLS section. These can be found in the JSON response to a "/api" request. This occurs when the --api flag is used and the API is publicly reachable and exposed without sufficient access control, contrary to the API documentation.
Recommendations For Containous Traefik versions 1.7.x through 1.7.11, restrict access to the "/api" endpoint to minimize the risk of exploitation. As a temporary workaround, consider disabling the API or limiting its exposure to prevent unauthorized access until a patch is available. Ensure proper access control is implemented according to the API documentation to prevent public reachability and exposure of sensitive information.

Exploit

Correção

Insufficiently Protected Credentials

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2019-2525
ALT-PU-2019-2564
CVE-2019-12452
GHSA-R3FQ-CMMW-CPMM
GO-2023-1919

Produtos afetados

Alt Linux
Traefik