Skip to content

x/vulndb: potential Go vuln in github.com/traefik/traefik/v3: GHSA-hxr6-2p24-hf98 #3342

New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

Closed
GoVulnBot opened this issue Dec 17, 2024 · 2 comments
Labels

Comments

@GoVulnBot
Copy link

Advisory GHSA-hxr6-2p24-hf98 references a vulnerability in the following Go modules:

Module
github.com/traefik/traefik
github.com/traefik/traefik/v2
github.com/traefik/traefik/v3

Description:
There is a potential vulnerability in Traefik managing HTTP/3 connections.

More details in the CVE-2024-53259.

Patches

Workarounds

No workaround

For more information

If you have any questions or comments about this advisory, please open an issue.

References:

Cross references:

See doc/quickstart.md for instructions on how to triage this report.

id: GO-ID-PENDING
modules:
    - module: github.com/traefik/traefik
      vulnerable_at: 1.7.34
    - module: github.com/traefik/traefik/v2
      versions:
        - fixed: 2.11.15
      vulnerable_at: 2.11.14
    - module: github.com/traefik/traefik/v3
      versions:
        - fixed: 3.2.2
      vulnerable_at: 3.2.1
summary: Traefik affected by CVE-2024-53259 in github.com/traefik/traefik
ghsas:
    - GHSA-hxr6-2p24-hf98
references:
    - advisory: https://github.com/advisories/GHSA-hxr6-2p24-hf98
    - advisory: https://github.com/traefik/traefik/security/advisories/GHSA-hxr6-2p24-hf98
    - web: https://github.com/traefik/traefik/releases/tag/v2.11.15
    - web: https://github.com/traefik/traefik/releases/tag/v3.2.2
source:
    id: GHSA-hxr6-2p24-hf98
    created: 2024-12-17T16:01:18.278462255Z
review_status: UNREVIEWED

@gopherbot
Copy link
Contributor

Change https://go.dev/cl/638116 mentions this issue: data/reports: add 6 unreviewed reports

@gopherbot
Copy link
Contributor

Change https://go.dev/cl/637956 mentions this issue: data/reports: add 6 unreviewed reports

# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
Projects
None yet
Development

No branches or pull requests

3 participants