
Cloud Vulnerability DB
A community-led vulnerabilities database
A moderate severity vulnerability (GHSA-7f4j-64p6-5h5v) was identified in Traefik related to HTTP/2 CONTINUATION flood in net/http. The vulnerability affects Traefik versions ≤ v2.11.1 and ≤ v3.0.0-rc4, and is associated with CVE-2023-45288. The issue was disclosed and patched on April 15, 2024, with fixes released in versions v2.11.2 and v3.0.0-rc5 (GitHub Advisory).
The vulnerability is related to the management of HTTP/2 connections in Traefik, specifically concerning HTTP/2 CONTINUATION flood handling in the net/http package. The issue has been classified as moderate severity, though specific CVSS scores are not provided in the available sources (Traefik Advisory).
While the full extent of the impact is not detailed in the available sources, the vulnerability affects HTTP/2 connection handling in Traefik installations running vulnerable versions (GitHub Release).
The vulnerability has been patched in Traefik versions v2.11.2 and v3.0.0-rc5. Users are advised to upgrade to these patched versions as no alternative workarounds are available (Traefik Release, RC5 Release).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."