hi is there any fixes for below CVE using v2.10.7
CVE-2023-6237
CVE-2024-0727
CVE-2023-48795
CVE-2023-6129
Maybe check
- CVE-2023-6237: it's an OpenSSL CVE, Traefik doesn't OpensSSL
- CVE-2024-0727 is also related to OpenSSL
- CVE-2023-48795: is about OpenSSH, Traefik doesn't use it.
- CVE-2023-6129 is also related to OpenSSL
Traefik doesn't need to fix CVE that doesn't impact it.
We got the above vulnerability for the traefik images
The CVE that is mentioned is not covered
We (Traefik Maintainers) maintain only the latest versions: v2.11 and v3.0
Same thing for the Docker images.
Those CVEs are false positives in the context of Traefik because Traefik doesn't use OpenSSL or OpenSSH.
Feel free to create your own custom Docker image if needed.
Thanks, for the info.
are there any fixes for below.
CVE-2023-28840
CVE-2023-49295
CVE-2023-28841
CVE-2023-28842
- CVE-2023-28840: Traefik is not impacted because it only uses the API client of Docker.
- CVE-2023-49295: already fixed
- CVE-2023-28841: Traefik is not impacted because it only uses the API client of Docker.
- CVE-2023-28842: Traefik is not impacted because it only uses the API client of Docker.
In all cases, we ONLY maintain v2.11 and v3.0.
This topic was automatically closed 3 days after the last reply. New replies are no longer allowed.