Several CVE's present on the latest traefik version

Do we have an ETA on when will these CVE's get resolved?

Here is the list

CVE-2022-40716
CVE-2023-28840
CVE-2023-28841
CVE-2023-28842

Hello,

Traefik is not impacted by those CVEs, I already answer this in several topics inside this forum and GitHub issues.

Answers:

TLDR:
Traefik is not impacted by those CVEs.

Link to the CVEs:

  • CVE-2022-40716: HashiCorp Consul and Consul Enterprise do not check for multiple SAN URI values in a CSR on the internal RPC endpoint.
  • CVE-2023-28840: moby/moby's dockerd daemon encrypted overlay network may be unauthenticated
  • CVE-2023-28841: moby/moby's dockerd daemon encrypted overlay network traffic may be unencrypted
  • CVE-2023-28842: moby/moby's dockerd daemon encrypted overlay network with a single endpoint is unauthenticated
1 Like

This topic was automatically closed 3 days after the last reply. New replies are no longer allowed.