Apache Traffic Server: Vulnerability in Field Names Allows Request Smuggling and Cache Poisoning
CVE-2023-38522
What is CVE-2023-38522?
Apache Traffic Server allows the acceptance of non-standard characters in HTTP field names, which can lead to the forwarding of malformed requests to origin servers. This behavior poses serious risks, including the potential for request smuggling attacks, where adversaries can manipulate the flow of requests to deceive application logic. Additionally, if the origin servers have their own vulnerabilities, this exploitation could facilitate cache poisoning, impacting the integrity and availability of cached content. Users are advised to upgrade to the patched versions (8.1.11 or 9.2.5) to mitigate these risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Apache Traffic Server 8.0.0 <= 8.1.10
Apache Traffic Server 9.0.0 <= 9.2.4
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved