QID 87522

Date Published: 2022-09-27

QID 87522: Apache Traffic Server Multiple Vulnerabilities

Apache Traffic Server is a fast, scalable and extensible HTTP/1.1 and HTTP/2.0 compliant caching proxy server.

ATS is vulnerable to potential smuggle and MITM attacks
Version Affected:
ATS 7.0.0 to 7.1.12
ATS 8.0.0 to 8.1.1
ATS 9.0.0 to 9.0.1
QID Detection Logic:
This unauthenticated QID relies on the version reported by the ATS service.

It allows an attacker to perform multiple attacks like cache poisoning, buffer overflow, and Denial of Service.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Customers are advised to upgrade to Apache Traffic Server 8.1.2, 9.0.2 or later versions to remediate these vulnerabilities.
    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    CVE-2021-32567 URL Logo lists.apache.org/thread/c6qkdb4srn6xksgmztw82p6srmo2kmq1