CVE-2024-39321

CVSS V2 None CVSS V3 None
Description
Traefik is an HTTP reverse proxy and load balancer. Versions prior to 2.11.6, 3.0.4, and 3.1.0-rc3 have a vulnerability that allows bypassing IP allow-lists via HTTP/3 early data requests in QUIC 0-RTT handshakes sent with spoofed IP addresses. Versions 2.11.6, 3.0.4, and 3.1.0-rc3 contain a patch for this issue. No known workarounds are available.
Overview
  • CVE ID
  • CVE-2024-39321
  • Assigner
  • GitHub_M
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2024-07-05T17:32:06.688Z
  • Last Modified Date
  • 2024-07-05T20:07:14.424Z
History
Created Old Value New Value Data Type Notes
2024-07-06 13:07:26 Added to TrackCVE