FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

traefik -- Use of vulnerable Go module x/net/http2

Affected packages
traefik < 2.9.8

Details

VuXML ID 428922c9-b07e-11ed-8700-5404a68ad561
Discovery 2022-10-22
Entry 2023-02-19

The Go project reports:

A request smuggling attack is possible when using MaxBytesHandler. When using MaxBytesHandler, the body of an HTTP request is not fully consumed. When the server attempts to read HTTP2 frames from the connection, it will instead be reading the body of the HTTP request, which could be attacker-manipulated to represent arbitrary HTTP2 requests.

References

CVE Name CVE-2022-41721
URL https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41721