VDB
Sign up
HIGH7.5

GHSA-3wqc-mwfx-672p

Traefik affected by Go oauth2/jws Improper Validation of Syntactic Correctness of Input vulnerability

Quick fix

GHSA-3wqc-mwfx-672p — github.com/traefik/traefik/v3: upgrade to the fixed version with the command below.

go get github.com/traefik/traefik/v3@v3.3.6

Details

### Summary We have encountered a security vulnerability being reported by our scanners for Traefik 2.11.22. - https://security.snyk.io/vuln/SNYK-CHAINGUARDLATEST-TRAEFIK33-9403297

### Details It seems to target oauth2/jws library.

### PoC No steps to replicate this vulnerability

### Impact We have a strict control on security and we always try to stay up-to-date with the fixes received for third-party solutions.

## Patches

- https://github.com/traefik/traefik/releases/tag/v2.11.24 - https://github.com/traefik/traefik/releases/tag/v3.3.6 - https://github.com/traefik/traefik/releases/tag/v3.4.0-rc2

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/traefik/traefik/v3
Introduced in: 0Fixed in: 3.3.6
Fixgo get github.com/traefik/traefik/v3@v3.3.6
Go/github.com/traefik/traefik/v2
Introduced in: 0Fixed in: 2.11.24
Fixgo get github.com/traefik/traefik/v2@v2.11.24
Go/github.com/traefik/traefik/v3
Introduced in: 3.4.0-rc1Fixed in: 3.4.0-rc2
Fixgo get github.com/traefik/traefik/v3@v3.4.0-rc2

References