CVE-2020-9321: High severity Traefik traefik vulnerability
configurationwatcher.go in Traefik 2.x before 2.1.4 and TraefikEE 2.0.0 mishandles the purging of certificate contents from providers before logging.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Traefik 2.xto a version that resolves this vulnerability.Fixed in 2.1.4 - Upgrade
Upgrade
TraefikEEto a version that resolves this vulnerability.Fixed in 2.0.0
Event History
Frequently Asked Questions
What is the vulnerability ID of this Traefik issue?
The vulnerability ID is CVE-2020-9321.
What is the severity rating of CVE-2020-9321?
The severity rating of CVE-2020-9321 is high (7.5).
Which versions of Traefik are affected by CVE-2020-9321?
Traefik versions 2.x before 2.1.4 and TraefikEE 2.0.0 are affected by CVE-2020-9321.
How does CVE-2020-9321 impact the affected software?
CVE-2020-9321 mishandles the purging of certificate contents from providers before logging in Traefik 2.x before 2.1.4 and TraefikEE 2.0.0.
How can I fix CVE-2020-9321?
To fix CVE-2020-9321, update Traefik to version 2.1.4 or newer. The fix can be found in the Traefik release v2.1.4.