GHSA-468w-8x39-gj5v

    Dashboard / Vulnerabilities / GHSA-468w-8x39-gj5v

    GHSA-468w-8x39-gj5v

    Published: 8 Dec 2022Last Modified: 7 Aug 2026

    Summary: Traefik routes exposed with an empty TLSOption

    Details: ## Impact There is a potential vulnerability in Traefik managing the TLS connections. A router configured with a not well-formatted [TLSOption](https://doc.traefik.io/traefik/v2.9/https/tls/#tls-options) is exposed with an empty TLSOption. For instance, a route secured using an mTLS connection set with a wrong CA file is exposed without verifying the client certificates. ## Patches https://github.com/traefik/traefik/releases/tag/v2.9.6 ## Workarounds Check the logs to detect the following error messages and fix your TLS options: - Empty CA: ``` {"level":"error","msg":"invalid clientAuthType: RequireAndVerifyClientCert, CAFiles is required","routerName":"Router0@file"} ``` - Bad CA content (or bad path): ``` {"level":"error","msg":"invalid certificate(s) content","routerName":"Router0@file"} ``` - Unknown Client Auth Type: ``` {"level":"error","msg":"unknown client auth type \"FooClientAuthType\"","routerName":"Router0@file"} ``` - Invalid cipherSuites ``` {"level":"error","msg":"invalid CipherSuite: foobar","routerName":"Router0@file"} ``` - Invalid curvePreferences ``` {"level":"error","msg":"invalid CurveID in curvePreferences: foobar","routerName":"Router0@file"} ``` ## For more information If you have any questions or comments about this advisory, please [open an issue](https://github.com/traefik/traefik/issues).

    Affected packages

    Package

    Name: github.com/traefik/traefik/v2

    Purl: pkg:golang/github.com/traefik/traefik/v2

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -2.9.6

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-468w-8x39-gj5v | CVE-DB