CVE-2018-15598: High severity traefik vulnerability
Containous Traefik 1.6.x before 1.6.6, when --api is used, exposes the configuration and secret if authentication is missing and the API's port is publicly reachable.
Other sources
Containous Traefik 1.6.x before 1.6.6, when --api is used, exposes the configuration and secret if authentication is missing and the API's port is publicly reachable.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-15598?
CVE-2018-15598 is a vulnerability in Containous Traefik 1.6.x before 1.6.6 that exposes the configuration and secret if authentication is missing and the API's port is publicly reachable.
How does CVE-2018-15598 affect Containous Traefik?
CVE-2018-15598 affects Containous Traefik 1.6.x versions before 1.6.6 when the `--api` flag is used.
What is the severity of CVE-2018-15598?
CVE-2018-15598 has a severity value of 7.5 (high).
How can I fix CVE-2018-15598?
To fix CVE-2018-15598, upgrade to Containous Traefik version 1.6.6 or higher.
Where can I find more information about CVE-2018-15598?
More information about CVE-2018-15598 can be found on the NIST National Vulnerability Database (NVD) website and the GitHub page of Containous Traefik.