# Vulnerability for v2.10.7

**URL:** <https://community.traefik.io/t/vulnerability-for-v2-10-7/22502>\
**Category:** Traefik v2\
**Tags:** docker\
**Created:** [April 29, 2024, 7:41pm UTC](https://community.traefik.io/t/vulnerability-for-v2-10-7/22502 "2024-04-29T19:41:09Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![gopi](https://avatars.discourse-cdn.com/v4/letter/g/7cd45c/32.png) [@gopi](https://community.traefik.io/u/gopi)\
**Post date:** [April 29, 2024, 7:41pm UTC](https://community.traefik.io/t/vulnerability-for-v2-10-7/22502/1 "2024-04-29T19:41:09Z")

</div>

hi is there any fixes for below CVE using v2.10.7  
CVE-2023-6237  
CVE-2024-0727  
CVE-2023-48795  
CVE-2023-6129

---

<div class="post-metadata">

**Author:** ![bluepuma77](https://avatars.discourse-cdn.com/v4/letter/b/a9adbd/32.png) [@bluepuma77](https://community.traefik.io/u/bluepuma77)\
**Post date:** [April 29, 2024, 8:51pm UTC](https://community.traefik.io/t/vulnerability-for-v2-10-7/22502/2 "2024-04-29T20:51:30Z")

</div>

Maybe check

> [@New Security Updates for Traefik 2.10 (2.10.6) and 3.0 (3.0.0-beta5)](https://community.traefik.io/t/new-security-updates-for-traefik-2-10-2-10-6-and-3-0-3-0-0-beta5/20680/):
>
> On November 28, 2023, we patched the following vulnerabilities with Traefik Proxy 2.10.6 and 3.0.0-beta5: [CVE-2023-45283](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-45283)[CVE-2023-45284](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-45284)[CVE-2023-47124](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-47124) (Fixed with the PR [#10224](https://github.com/traefik/traefik/pull/10224)) [CVE-2023-47633](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-47633) (Fixed with the PR [#10242](https://github.com/traefik/traefik/pull/10242)) [CVE-2023-47106](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-47106) (Fixed with the PR [#10229](https://github.com/traefik/traefik/pull/10229)) If you have any questions or comments about these vulnerabilities, please add a comment.

> [@New Security Updates for Traefik 2.11 (2.11.2) and 3.0 (3.0.0-rc5)](https://community.traefik.io/t/new-security-updates-for-traefik-2-11-2-11-2-and-3-0-3-0-0-rc5/22286/):
>
> On April 11, 2024, we patched the following vulnerabilities with Traefik Proxy 2.11.2 and 3.0.0-rc5: [GHSA-7f4j-64p6-5h5v](https://github.com/traefik/traefik/security/advisories/GHSA-7f4j-64p6-5h5v) (related to [CVE-2023-45288](https://www.cve.org/CVERecord?id=CVE-2023-45288)) [CVE-2024-28869](https://www.cve.org/CVERecord?id=CVE-2024-28869) If you have any questions or comments about these vulnerabilities, please add a comment.

---

<div class="post-metadata">

**Author:** ![ldez](https://sea2.discourse-cdn.com/flex020/user_avatar/community.traefik.io/ldez/32/5_2.png) [@ldez](https://community.traefik.io/u/ldez)\
**Post date:** [April 30, 2024, 12:09am UTC](https://community.traefik.io/t/vulnerability-for-v2-10-7/22502/3 "2024-04-30T00:09:48Z")

</div>

- [CVE-2023-6237](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-6237): it's an OpenSSL CVE, Traefik doesn't OpensSSL
- [CVE-2024-0727](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-0727) is also related to OpenSSL
- [CVE-2023-48795](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-48795): is about OpenSSH, Traefik doesn't use it.
- [CVE-2023-6129](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-6129) is also related to OpenSSL

Traefik doesn't need to fix CVE that doesn't impact it.

---

<div class="post-metadata">

**Author:** ![gopi](https://avatars.discourse-cdn.com/v4/letter/g/7cd45c/32.png) [@gopi](https://community.traefik.io/u/gopi)\
**Post date:** [April 30, 2024, 12:12am UTC](https://community.traefik.io/t/vulnerability-for-v2-10-7/22502/4 "2024-04-30T00:12:56Z")

</div>

We got the above vulnerability for the traefik images

---

<div class="post-metadata">

**Author:** ![gopi](https://avatars.discourse-cdn.com/v4/letter/g/7cd45c/32.png) [@gopi](https://community.traefik.io/u/gopi)\
**Post date:** [April 30, 2024, 12:13am UTC](https://community.traefik.io/t/vulnerability-for-v2-10-7/22502/5 "2024-04-30T00:13:39Z")

</div>

The CVE that is mentioned is not covered

---

<div class="post-metadata">

**Author:** ![ldez](https://sea2.discourse-cdn.com/flex020/user_avatar/community.traefik.io/ldez/32/5_2.png) [@ldez](https://community.traefik.io/u/ldez)\
**Post date:** [April 30, 2024, 12:16am UTC](https://community.traefik.io/t/vulnerability-for-v2-10-7/22502/6 "2024-04-30T00:16:25Z")

</div>

We (Traefik Maintainers) maintain only the latest versions: v2.11 and v3.0

Same thing for the Docker images.

Those CVEs are false positives in the context of Traefik because Traefik doesn't use OpenSSL or OpenSSH.

Feel free to create your own custom Docker image if needed.

---

<div class="post-metadata">

**Author:** ![gopi](https://avatars.discourse-cdn.com/v4/letter/g/7cd45c/32.png) [@gopi](https://community.traefik.io/u/gopi)\
**Post date:** [April 30, 2024, 12:25am UTC](https://community.traefik.io/t/vulnerability-for-v2-10-7/22502/7 "2024-04-30T00:25:17Z")

</div>

Thanks, for the info.  
are there any fixes for below.

CVE-2023-28840  
CVE-2023-49295  
CVE-2023-28841  
CVE-2023-28842

---

<div class="post-metadata">

**Author:** ![ldez](https://sea2.discourse-cdn.com/flex020/user_avatar/community.traefik.io/ldez/32/5_2.png) [@ldez](https://community.traefik.io/u/ldez)\
**Post date:** [April 30, 2024, 12:28am UTC](https://community.traefik.io/t/vulnerability-for-v2-10-7/22502/8 "2024-04-30T00:28:22Z")

</div>

- [CVE-2023-28840](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-28840): Traefik is not impacted because it only uses the API client of Docker.
- [CVE-2023-49295](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-49295): already fixed
- [CVE-2023-28841](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-28841): Traefik is not impacted because it only uses the API client of Docker.
- [CVE-2023-28842](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-28842): Traefik is not impacted because it only uses the API client of Docker.

In all cases, we ONLY maintain v2.11 and v3.0.

> **[Releases - Traefik](https://doc.traefik.io/traefik/deprecation/releases/)**
>
> Traefik Documentation

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex020/uploads/containo/original/2X/b/bd81ebdb578656e76e56ff3cc3eed021d3ba132d.png) [@system](https://community.traefik.io/u/system)\
**Post date:** [May 3, 2024, 12:29am UTC](https://community.traefik.io/t/vulnerability-for-v2-10-7/22502/9 "2024-05-03T00:29:18Z")

</div>

This topic was automatically closed 3 days after the last reply. New replies are no longer allowed.
