Lucene search

K
prionPRIOn knowledge basePRION:CVE-2023-29013
HistoryApr 14, 2023 - 7:15 p.m.

Design/Logic Flaw

2023-04-1419:15:00
PRIOn knowledge base
www.prio-n.com
13
traefik
vulnerability
http header parsing
denial of service
patch
nvd

7.2 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

39.7%

Traefik (pronounced traffic) is a modern HTTP reverse proxy and load balancer for deploying microservices. There is a vulnerability in Go when parsing the HTTP headers, which impacts Traefik. HTTP header parsing could allocate substantially more memory than required to hold the parsed headers. This behavior could be exploited to cause a denial of service. This issue has been patched in versions 2.9.10 and 2.10.0-rc2.

CPENameOperatorVersion
traefikeq2.10.0 rc1
traefiklt2.9.10

7.2 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

39.7%