CVE-2019-12452 Information

Description

types/types.go in Containous Traefik 1.7.x through 1.7.11 when the –api flag is used and the API is publicly reachable and exposed without sufficient access control (which is contrary to the API documentation) allows remote authenticated users to discover password hashes by reading the Basic HTTP Authentication or Digest HTTP Authentication section or discover a key by reading the ClientTLS section. These can be found in the JSON response to a /api request.

CVSS Vector

CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Reference

https://docs.traefik.io/configuration/api/security https://github.com/containous/traefik/issues/4917 https://github.com/containous/traefik/pull/4918

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction Required

LOW

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

HIGH

Availability Impact

HIGH

Base Score

HIGH

Base Severity

7.5

Share on: