QID 87472

Date Published: 2021-11-22

QID 87472: Apache Traffic Server Multiple Vulnerabilities

Apache Traffic Server is a fast, scalable and extensible HTTP/1.1 and HTTP/2.0 compliant caching proxy server.

Apache Traffic Server is vulnerable to various smuggle, DOS, and validation attacks
Version Affected:
ATS 8.0.0 to 8.1.2
ATS 9.0.0 to 9.1.0
QID Detection Logic:
This unauthenticated QID relies on the version reported by the ATS service.

Vulnerable version are prone to various smuggle, DOS, and validation attacks.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Customers are advised to upgrade to Apache Traffic Server 8.1.3, 9.1.1 or later versions to remediate these vulnerabilities.
    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    Apache Traffic Server URL Logo lists.apache.org/thread/k01797hyncx53659wr3o72s5cvkc3164