Sploitus

CVE-2022-23632

No indexed exploits for CVE-2022-23632 yet

Traefik is an HTTP reverse proxy and load balancer. Prior to version 2.6.1, Traefik skips the router transport layer security (TLS) configuration when the host header is a fully qualified domain name (FQDN). For a request, the TLS configuration choice can be different than the router choice, which implies the use of a wrong TLS configuration. When sending a request using FQDN handled by a router configured with a dedicated TLS configuration, the TLS configuration falls back to the default configuration that might not correspond to the configured one. If the CNAME flattening is enabled, the selected TLS configuration is the SNI one and the routing uses the CNAME value, so this can skip the expected TLS configuration. Version 2.6.1 contains a patch for this issue. As a workaround, one may add the FDQN to the host rule. However, there is no workaround if the CNAME flattening is enabled.

Affected products
Alt Linux, Traefik
Traefik
< 2.6.1
Fix
Available
CVSS 3.1
7.5 HIGH
EPSS
1.7% (75th percentile)
Weakness
CWE-295
NVD status
Modified
Published
2022-02-17
CVE-2022-23632 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2022-23632 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2022-23632 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.