Skip to content

x/vulndb: potential Go vuln in github.com/traefik/traefik/v2: GHSA-c6hx-pjc3-7fqr #1057

New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

Closed
GoVulnBot opened this issue Oct 10, 2022 · 2 comments
Labels
excluded: DEPENDENT_VULNERABILITY This vulnerability is downstream of another existing vulnerability report.

Comments

@GoVulnBot
Copy link

In GitHub Security Advisory GHSA-c6hx-pjc3-7fqr, there is a vulnerability in the following Go packages or modules:

Unit Fixed Vulnerable Ranges
github.com/traefik/traefik/v2 2.9.0-rc5 >= 2.9.0-rc1, < 2.9.0-rc5

See doc/triage.md for instructions on how to triage this report.

modules:
  - module: TODO
    versions:
      - introduced: 2.9.0-rc1
        fixed: 2.9.0-rc5
    packages:
      - package: github.com/traefik/traefik/v2
  - module: TODO
    versions:
      - fixed: 2.8.8
    packages:
      - package: github.com/traefik/traefik/v2
description: |
    ### Impact

    There is a potential vulnerability in Traefik managing HTTP/2 connections.
    A closing HTTP/2 server connection could hang forever because of a subsequent fatal error. This failure mode could be exploited to cause a denial of service.

    ### Patches

    Traefik v2.8.x: https://github.com/traefik/traefik/releases/tag/v2.8.8
    Traefik v2.9.x: https://github.com/traefik/traefik/releases/tag/v2.9.0-rc5

    ### Workarounds

    No workaround.

    ### For more information

    If you have any questions or comments about this advisory, please [open an issue](https://github.com/traefik/traefik/issues).
cves:
  - CVE-2022-39271
ghsas:
  - GHSA-c6hx-pjc3-7fqr

@neild
Copy link
Contributor

neild commented Oct 12, 2022

This is #969.

@tatianab tatianab added excluded: DEPENDENT_VULNERABILITY This vulnerability is downstream of another existing vulnerability report. and removed NeedsTriage labels Oct 12, 2022
@gopherbot
Copy link
Contributor

Change https://go.dev/cl/443397 mentions this issue: data/excluded: add GO-2022-1057.yaml for CVE-2022-39271

# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
excluded: DEPENDENT_VULNERABILITY This vulnerability is downstream of another existing vulnerability report.
Projects
None yet
Development

No branches or pull requests

4 participants