{"id":"GHSA-rvj4-q8q5-8grf","aliases":["GO-2024-2941"],"title":"ACME DNS: Azure Identity Libraries Elevation of Privilege Vulnerability","summary":"ACME DNS: Azure Identity Libraries Elevation of Privilege Vulnerability","severity":"medium","cvss":5.5,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","vendor":"traefik","product":"github.com/traefik/traefik/v3","ecosystem":"go","affected":["github.com/traefik/traefik/v3 < 3.0.3","github.com/traefik/traefik/v2 < 2.11.5"],"patched":["github.com/traefik/traefik/v3 3.0.3","github.com/traefik/traefik/v2 2.11.5"],"published":"2024-06-20","updated":"2026-08-07","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-rvj4-q8q5-8grf","references":[{"url":"https://github.com/traefik/traefik/security/advisories/GHSA-rvj4-q8q5-8grf"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2024-35255"},{"url":"https://github.com/traefik/traefik"},{"url":"https://github.com/traefik/traefik/releases/tag/v2.11.5"},{"url":"https://github.com/traefik/traefik/releases/tag/v3.0.3"}],"tags":["osv","go"],"ingestedAt":"2026-08-07T19:14:17.661Z","slug":"GHSA-rvj4-q8q5-8grf","body":"## Overview\n\n### Impact\n\nThere is a vulnerability in [Azure Identity Libraries and Microsoft Authentication Library Elevation of Privilege Vulnerability](https://nvd.nist.gov/vuln/detail/CVE-2024-35255).\n\n### References\n\n- [CVE-2024-35255](https://nvd.nist.gov/vuln/detail/CVE-2024-35255)\n\n### Patches\n\n- https://github.com/traefik/traefik/releases/tag/v2.11.5\n- https://github.com/traefik/traefik/releases/tag/v3.0.3\n\n### Workarounds\n\nNo workaround.\n\n### For more information\n\nIf you have any questions or comments about this advisory, please [open an issue](https://github.com/traefik/traefik/issues).\n\n## Affected packages\n\n- `github.com/traefik/traefik/v3 < 3.0.3`\n- `github.com/traefik/traefik/v2 < 2.11.5`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `github.com/traefik/traefik/v3 3.0.3`\n- `github.com/traefik/traefik/v2 2.11.5`","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":30.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}