Romain
6 exploits
Active since Dec 2022
Traefik Kubernetes CRD allows unauthorized cross-namespace middleware binding
CVSS 6.4
Traefik < 2.9.6 - Improper Certificate Validation in TLSOption Configuration
CVSS 8.1
Traefik < 2.11.2 and 3.0.0-beta3-3.0.0-rc5 - Denial of Service via Content-Length Header
CVSS 7.5
Traefik < 2.11.25 and < 3.4.1 - Path Traversal via URL-Encoded Path Bypass
CVSS 9.1
Traefik 3.5.0-3.6.2 - Improper Certificate Validation via proxy-ssl-verify Annotation
CVSS 5.9
Traefik < 3.6.8 - Unauthenticated Denial of Service via STARTTLS Request Bypass
CVSS 7.5