Apache Traffic Server Vulnerability Affects Cache Lookup and Forwarding Requests
CVE-2024-35296
8.2HIGH
What is CVE-2024-35296?
A vulnerability exists in Apache Traffic Server that arises from an invalid Accept-Encoding header, causing disruptions in cache lookup processes. This flaw can result in forced request forwarding, which may inadvertently expose systems to operational inefficiencies or security risks. It affects multiple versions of Apache Traffic Server, specifically from 8.0.0 through 8.1.10 and from 9.0.0 through 9.2.4. To mitigate potential impacts, users are strongly advised to update to versions 8.1.11 or 9.2.5, which contain the necessary patches to address this issue.
Affected Version(s)
Apache Traffic Server 8.0.0 <= 8.1.10
Apache Traffic Server 9.0.0 <= 9.2.4