Improper Authentication
High severity
GitHub Reviewed
Published
Sep 2, 2021
to the GitHub Advisory Database
•
Updated Feb 1, 2023
Description
Published by the National Vulnerability Database
Jul 2, 2020
Reviewed
Aug 2, 2021
Published to the GitHub Advisory Database
Sep 2, 2021
Last updated
Feb 1, 2023
Traefik 2.x, in certain configurations, allows HTTPS sessions to proceed without mutual TLS verification in a situation where ERR_BAD_SSL_CLIENT_AUTH_CERT should have occurred.
References