QID 87491

Date Published: 2022-05-12

QID 87491: Apache Traffic Server Multiple Vulnerabilities

Apache Traffic Server is a fast, scalable and extensible HTTP/1.1 and HTTP/2.0 compliant caching proxy server.

ATS is vulnerable to potential smuggle and MITM attacks
Version Affected:
ATS 8.0.0 to 8.1.3
ATS 9.0.0 to 9.1.1
QID Detection Logic:
This unauthenticated QID relies on the version reported by the ATS service.

ATS is vulnerable to potential smuggle and MITM attacks

  • CVSS V3 rated as Critical - 8.1 severity.
  • CVSS V2 rated as High - 6.8 severity.
  • Solution
    Customers are advised to upgrade to Apache Traffic Server 8.1.4, 9.1.2 or later versions to remediate these vulnerabilities.
    Vendor References

    CVEs related to QID 87491

    Software Advisories
    Advisory ID Software Component Link
    Apache Traffic Server URL Logo lists.apache.org/thread/zblwzcfs9ryhwjr89wz4osw55pxm6dx6