Containous Traefik 1.6.x before 1.6.6, when --api is used, exposes the configuration and secret if authentication is missing and the API's port is publicly reachable.
https://github.com/containous/traefik/pull/3790/commits/368bd170913078732bde58160f92f202f370278b
https://github.com/containous/traefik/pull/3790/commits/113250ce5735d554c502ca16fb03bb9119ca79f1
https://github.com/containous/traefik/pull/3790
https://github.com/containous/traefik/releases/tag/v1.6.6
Source: Mitre, NVD
Published: 2018-08-21
Updated: 2024-11-21
Base Score: 5
Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N
Severity: Medium
Base Score: 7.5
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Severity: High
EPSS: 0.00412