VDB
CVE-2023-47106
CVE-2023-47106
PUBLISHED
CVSS 4.800000190734863 MEDIUM
Traefik incorrectly processes fragment in the URL, leads to Authorization Bypass
EPSS 0.13% · 31.8th percentile
Risk Scores
CVSS v3.1
4.800000190734863
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
EPSS Score
0.13%
31.8th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| github.com | traefik/traefik/v2 | 0, 0 |
| github.com | traefik/traefik/v3 | 0, 0 |
| traefik | traefik | 3.0.0, 3.0.0, 3.0.0 |
Timeline
- Dec 4, 2023 CVE Published
- Dec 5, 2023 EPSS Score
- Dec 23, 2023 PoC Published
- Jan 3, 2024 EPSS Score
- Feb 2, 2024 EPSS Score
- Mar 2, 2024 EPSS Score
- Apr 1, 2024 EPSS Score
- Apr 30, 2024 EPSS Score
- May 30, 2024 EPSS Score
- Jun 28, 2024 EPSS Score
- Jul 28, 2024 EPSS Score
- Aug 26, 2024 EPSS Score
References
- https://github.com/traefik/traefik/security/advisories/GHSA-fvhj-4qfh-q2hm url
- https://datatracker.ietf.org/doc/html/rfc7230#section-5.3.1 url
- https://github.com/traefik/traefik/releases/tag/v2.10.6 url
- https://github.com/traefik/traefik/releases/tag/v3.0.0-beta5 url
- https://nvd.nist.gov/vuln/detail/CVE-2023-47106 advisory
- https://github.com/traefik/traefik package