This CPE summary could be partial or incomplete. Please contact us for a detailed listing.

Summary

Detail
Vendor Apache First view 2014-08-22
Product Traffic Server Last view 2023-10-17
Version 3.3.1 Type Application
Update *  
Edition *  
Language *  
Sofware Edition *  
Target Software *  
Target Hardware *  
Other *  
 
CPE Product cpe:2.3:a:apache:traffic_server

Activity : Overall

Related : CVE

This CPE have more than 25 Relations. If you want to see a complete summary for this CPE, please contact us.
  Date Alert Description
7.5 2023-10-17 CVE-2023-41752

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Traffic Server.This issue affects Apache Traffic Server: from 8.0.0 through 8.1.8, from 9.0.0 through 9.2.2.

Users are recommended to upgrade to version 8.1.9 or 9.2.3, which fixes the issue.

7.5 2023-10-17 CVE-2023-39456

Improper Input Validation vulnerability in Apache Traffic Server with malformed HTTP/2 frames.This issue affects Apache Traffic Server: from 9.0.0 through 9.2.2.

Users are recommended to upgrade to version 9.2.3, which fixes the issue.

7.5 2023-10-10 CVE-2023-44487

The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.

9.1 2023-08-09 CVE-2023-33934

Improper Input Validation vulnerability in Apache Software Foundation Apache Traffic Server.This issue affects Apache Traffic Server: through 9.2.1.

7.5 2023-08-09 CVE-2022-47185

Improper input validation vulnerability on the range header in Apache Software Foundation Apache Traffic Server.This issue affects Apache Traffic Server: through 9.2.1.

7.5 2023-06-14 CVE-2023-33933

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache Traffic Server.This issue affects Apache Traffic Server: from 8.0.0 through 9.2.0.

8.x users should upgrade to 8.1.7 or later versions 9.x users should upgrade to 9.2.1 or later versions

7.5 2023-06-14 CVE-2023-30631

Improper Input Validation vulnerability in Apache Software Foundation Apache Traffic Server. The configuration option proxy.config.http.push_method_enabled didn't function. However, by default the PUSH method is blocked in the ip_allow configuration file.This issue affects Apache Traffic Server: from 8.0.0 through 9.2.0.

8.x users should upgrade to 8.1.7 or later versions 9.x users should upgrade to 9.2.1 or later versions

7.5 2023-06-14 CVE-2022-47184

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache Traffic Server.This issue affects Apache Traffic Server: 8.0.0 to 9.2.0.

6.1 2022-12-19 CVE-2022-40743

Improper Input Validation vulnerability for the xdebug plugin in Apache Software Foundation Apache Traffic Server can lead to cross site scripting and cache poisoning attacks.This issue affects Apache Traffic Server: 9.0.0 to 9.1.3. Users should upgrade to 9.1.4 or later versions.

5.3 2022-12-19 CVE-2022-37392

Improper Check for Unusual or Exceptional Conditions vulnerability in handling the requests to Apache Traffic Server. This issue affects Apache Traffic Server 8.0.0 to 9.1.2.

7.5 2022-12-19 CVE-2022-32749

Improper Check for Unusual or Exceptional Conditions vulnerability handling requests in Apache Traffic Server allows an attacker to crash the server under certain conditions.

This issue affects Apache Traffic Server: from 8.0.0 through 9.1.3.

7.5 2022-08-10 CVE-2022-31780

Improper Input Validation vulnerability in HTTP/2 frame handling of Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache Traffic Server 8.0.0 to 9.1.2.

7.5 2022-08-10 CVE-2022-31779

Improper Input Validation vulnerability in HTTP/2 header parsing of Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache Traffic Server 8.0.0 to 9.1.2.

7.5 2022-08-10 CVE-2022-31778

Improper Input Validation vulnerability in handling the Transfer-Encoding header of Apache Traffic Server allows an attacker to poison the cache. This issue affects Apache Traffic Server 8.0.0 to 9.0.2.

7.5 2022-08-10 CVE-2022-28129

Improper Input Validation vulnerability in HTTP/1.1 header parsing of Apache Traffic Server allows an attacker to send invalid headers. This issue affects Apache Traffic Server 8.0.0 to 9.1.2.

7.5 2022-08-10 CVE-2022-25763

Improper Input Validation vulnerability in HTTP/2 request validation of Apache Traffic Server allows an attacker to create smuggle or cache poison attacks. This issue affects Apache Traffic Server 8.0.0 to 9.1.2.

7.5 2022-08-10 CVE-2021-37150

Improper Input Validation vulnerability in header parsing of Apache Traffic Server allows an attacker to request secure resources. This issue affects Apache Traffic Server 8.0.0 to 9.1.2.

8.1 2022-03-23 CVE-2021-44759

Improper Authentication vulnerability in TLS origin validation of Apache Traffic Server allows an attacker to create a man in the middle attack. This issue affects Apache Traffic Server 8.0.0 to 8.1.0.

7.5 2022-03-23 CVE-2021-44040

Improper Input Validation vulnerability in request line parsing of Apache Traffic Server allows an attacker to send invalid requests. This issue affects Apache Traffic Server 8.0.0 to 8.1.3 and 9.0.0 to 9.1.1.

9.8 2021-11-03 CVE-2021-43082

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in the stats-over-http plugin of Apache Traffic Server allows an attacker to overwrite memory. This issue affects Apache Traffic Server 9.1.0.

7.5 2021-11-03 CVE-2021-41585

Improper Input Validation vulnerability in accepting socket connections in Apache Traffic Server allows an attacker to make the server stop accepting new connections. This issue affects Apache Traffic Server 5.0.0 to 9.1.0.

8.1 2021-11-03 CVE-2021-38161

Improper Authentication vulnerability in TLS origin verification of Apache Traffic Server allows for man in the middle attacks. This issue affects Apache Traffic Server 8.0.0 to 8.0.8.

7.5 2021-11-03 CVE-2021-37149

Improper Input Validation vulnerability in header parsing of Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache Traffic Server 8.0.0 to 8.1.2 and 9.0.0 to 9.1.0.

7.5 2021-11-03 CVE-2021-37148

Improper input validation vulnerability in header parsing of Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache Traffic Server 8.0.0 to 8.1.2 and 9.0.0 to 9.0.1.

7.5 2021-11-03 CVE-2021-37147

Improper input validation vulnerability in header parsing of Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache Traffic Server 8.0.0 to 8.1.2 and 9.0.0 to 9.1.0.

CWE : Common Weakness Enumeration

%idName
41% (20) CWE-20 Improper Input Validation
20% (10) CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggli...
8% (4) CWE-200 Information Exposure
6% (3) CWE-400 Uncontrolled Resource Consumption ('Resource Exhaustion')
4% (2) CWE-770 Allocation of Resources Without Limits or Throttling
4% (2) CWE-754 Improper Check for Unusual or Exceptional Conditions
4% (2) CWE-287 Improper Authentication
2% (1) CWE-787 Out-of-bounds Write
2% (1) CWE-668 Exposure of Resource to Wrong Sphere
2% (1) CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflo...
2% (1) CWE-119 Failure to Constrain Operations within the Bounds of a Memory Buffer
2% (1) CWE-79 Failure to Preserve Web Page Structure ('Cross-site Scripting')

Nessus® Vulnerability Scanner

id Description
2018-09-04 Name: The remote Debian host is missing a security-related update.
File: debian_DSA-4282.nasl - Type: ACT_GATHER_INFO
2018-03-08 Name: The remote caching server is affected by an input-validation vulnerability.
File: apache_traffic_server_712.nasl - Type: ACT_GATHER_INFO
2018-03-08 Name: The remote caching server is affected by an input-validation vulnerability.
File: apache_traffic_server_712_tls_handshake.nasl - Type: ACT_GATHER_INFO
2018-03-05 Name: The remote Debian host is missing a security-related update.
File: debian_DSA-4128.nasl - Type: ACT_GATHER_INFO
2015-07-06 Name: The remote Fedora host is missing a security update.
File: fedora_2015-10520.nasl - Type: ACT_GATHER_INFO
2015-07-06 Name: The remote Fedora host is missing a security update.
File: fedora_2015-10524.nasl - Type: ACT_GATHER_INFO
2015-01-22 Name: The remote caching server is affected by a denial of service vulnerability.
File: apache_traffic_server_501.nasl - Type: ACT_GATHER_INFO
2015-01-22 Name: The remote caching server is affected by a denial of service vulnerability.
File: apache_traffic_server_512.nasl - Type: ACT_GATHER_INFO
2014-09-08 Name: The remote FreeBSD host is missing a security-related update.
File: freebsd_pkg_6318b303350711e4b76c0011d823eebd.nasl - Type: ACT_GATHER_INFO
2014-08-09 Name: The remote Fedora host is missing a security update.
File: fedora_2014-8790.nasl - Type: ACT_GATHER_INFO