CVE-2018-15598 describes a critical information disclosure vulnerability in Containous Traefik versions 1.6.x prior to 1.6.6. When the --api flag is enabled without authentication and the API port is publicly accessible, an attacker can remotely access the Traefik configuration and sensitive secrets, including TLS certificate private keys. This vulnerability carries a high CVSS score of 7.5, indicating a severe risk due to its network-based attack vector, low attack complexity, and high confidentiality impact. While there is no evidence of active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered some community discussion and media coverage, highlighting its potential for significant data breaches.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.6.0, < 1.6.6CPE matchmatch criteria | cpe:2.3:a:traefik:traefik:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.