Cryptographic issues in Traefik - CVE-2022-23632
Published: July 19, 2022 / Updated: May 5, 2026
Vulnerability details
The vulnerability allows a remote attacker to perform MitM attack.
The vulnerability exists due to insecure TLS configuration choice when configuring mTLS between Traefik and clients. A remote attacker can force the application to use less secure TLS configuration, that can result in successful man-in-the-middle attacks.
Affected software
Oracle Communications Unified Inventory Management
Oracle Communications Order and Service Management