Skip to content

Traefik severity alert #910

Description

@sashakames

The Metagrid deployment pulls traefik:3.3 image from DockerHub. However, this version has several critical security errors. In fact, the latest traefik version that does not have a crit security score is v3.6.12.

https://hub.docker.com/_/traefik/tags  (Filter tags: "3.6.12", or prior "3.6 versions" i.e. "3.3" to view vulnerabilities)

The latest versions also have a "high" severity score, though those are still being reviewed by NIST. The security errors don't seem to stem from "traefik" itself, but its software stack dependencies.

Metadata

Metadata

Assignees

No one assigned

    Labels

    Level 3: HardBased on assignee's knowledgeType: ConfigurationProject configuration, settings, etc.Type: DependenciesPull requests that update a dependency file

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions