Containous Traefik 1.6.x before 1.6.6, when --api is used, exposes the configuration and secret if authentication is missing and the API's port is publicly reachable.
                
            References
                    | Link | Resource | 
|---|---|
| https://github.com/containous/traefik/pull/3790 | Third Party Advisory | 
| https://github.com/containous/traefik/pull/3790/commits/113250ce5735d554c502ca16fb03bb9119ca79f1 | Third Party Advisory | 
| https://github.com/containous/traefik/pull/3790/commits/368bd170913078732bde58160f92f202f370278b | Third Party Advisory | 
| https://github.com/containous/traefik/releases/tag/v1.6.6 | Release Notes | 
| https://github.com/containous/traefik/pull/3790 | Third Party Advisory | 
| https://github.com/containous/traefik/pull/3790/commits/113250ce5735d554c502ca16fb03bb9119ca79f1 | Third Party Advisory | 
| https://github.com/containous/traefik/pull/3790/commits/368bd170913078732bde58160f92f202f370278b | Third Party Advisory | 
| https://github.com/containous/traefik/releases/tag/v1.6.6 | Release Notes | 
Configurations
                    History
                    21 Nov 2024, 03:51
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () https://github.com/containous/traefik/pull/3790 - Third Party Advisory | |
| References | () https://github.com/containous/traefik/pull/3790/commits/113250ce5735d554c502ca16fb03bb9119ca79f1 - Third Party Advisory | |
| References | () https://github.com/containous/traefik/pull/3790/commits/368bd170913078732bde58160f92f202f370278b - Third Party Advisory | |
| References | () https://github.com/containous/traefik/releases/tag/v1.6.6 - Release Notes | 
Information
                Published : 2018-08-21 01:29
Updated : 2024-11-21 03:51
NVD link : CVE-2018-15598
Mitre link : CVE-2018-15598
CVE.ORG link : CVE-2018-15598
JSON object : View
Products Affected
                traefik
- traefik
CWE
                
                    
                        
                        CWE-287
                        
            Improper Authentication
