configurationwatcher.go in Traefik 2.x before 2.1.4 and TraefikEE 2.0.0 mishandles the purging of certificate contents from providers before logging.
References
| Link | Resource |
|---|---|
| https://github.com/containous/traefik/pull/6281 | Patch Third Party Advisory |
| https://github.com/containous/traefik/releases/tag/v2.1.4 | Release Notes |
| https://github.com/containous/traefik/pull/6281 | Patch Third Party Advisory |
| https://github.com/containous/traefik/releases/tag/v2.1.4 | Release Notes |
Configurations
Configuration 1 (hide)
|
History
06 Mar 2026, 15:25
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Traefik traefik Enterprise
|
|
| CPE | cpe:2.3:a:traefik:traefik_enterprise:2.0.0:*:*:*:*:*:*:* |
21 Nov 2024, 05:40
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/containous/traefik/pull/6281 - Patch, Third Party Advisory | |
| References | () https://github.com/containous/traefik/releases/tag/v2.1.4 - Release Notes |
Information
Published : 2020-03-16 19:15
Updated : 2026-03-06 15:25
NVD link : CVE-2020-9321
Mitre link : CVE-2020-9321
CVE.ORG link : CVE-2020-9321
JSON object : View
Products Affected
traefik
- traefik
- traefik_enterprise
CWE
CWE-295
Improper Certificate Validation
