CVE-2020-9321
MEDIUM5.3EPSS 0.15%Traefik has an Improper Certificate Handling issue
Published: 9/2/2021Modified: 3/6/2026
Description
configurationwatcher.go in Traefik 2.x before 2.1.4 and TraefikEE 2.0.0 mishandles the purging of certificate contents from providers before logging.
Affected packages (4)
- Go/github.com/containous/traefikfrom 0
- Go/github.com/containous/traefik/v2from 0, < 2.1.4
- Go/github.com/traefik/traefikfrom 0, < 2.1.4
- Go/github.com/traefik/traefikfrom 0
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM5.3 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C |
References (7)
- ADVISORYhttps://github.com/advisories/GHSA-7h6j-2268-fhcm
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2020-9321
- PATCHhttps://github.com/traefik/traefik
- WEBhttps://github.com/containous/traefik/pull/6281
- WEBhttps://github.com/containous/traefik/releases/tag/v2.1.4
- WEBhttps://github.com/traefik/traefik/pull/6281
- WEBhttps://github.com/traefik/traefik/releases/tag/v2.1.4