GMS-2022-8053: Traefik routes exposed with an empty TLSOption
There is a potential vulnerability in Traefik managing the TLS connections. A router configured with a not well-formatted TLSOption
is exposed with an empty TLSOption
. For instance, a route secured using an mTLS connection set with a wrong CA file is exposed without verifying the client certificates.
References
Detect and mitigate GMS-2022-8053 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →