Traefik
by Containous
CVEs (2)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-27375 | Med | 0.35 | 5.3 | 0.01 | Feb 18, 2021 | Traefik before 2.4.5 allows the loading of IFRAME elements from other domains. | ||
| CVE-2020-15129 | Med | 0.33 | 6.1 | 0.08 | Jul 30, 2020 | In Traefik before versions 1.7.26, 2.2.8, and 2.3.0-rc3, there exists a potential open redirect vulnerability in Traefik's handling of the "X-Forwarded-Prefix" header. The Traefik API dashboard component doesn't validate that the value of the header "X-Forwarded-Prefix" is a… |
- risk 0.35cvss 5.3epss 0.01
Traefik before 2.4.5 allows the loading of IFRAME elements from other domains.
- risk 0.33cvss 6.1epss 0.08
In Traefik before versions 1.7.26, 2.2.8, and 2.3.0-rc3, there exists a potential open redirect vulnerability in Traefik's handling of the "X-Forwarded-Prefix" header. The Traefik API dashboard component doesn't validate that the value of the header "X-Forwarded-Prefix" is a…