Traffic Server Improper Input Validation Vulnerability
CVE-2024-38479

7.5HIGH

Key Information:

Vendor

Apache

Vendor
CVE Published:
14 November 2024

What is CVE-2024-38479?

The vulnerability in Apache Traffic Server stems from insufficient input validation, potentially allowing an attacker to manipulate parameters, which may lead to unexpected behaviors or security breaches. Users running versions 8.0.0 to 8.1.11 and 9.0.0 to 9.2.5 are advised to upgrade to version 9.2.6 or newer to mitigate this risk.

Affected Version(s)

Apache Traffic Server 8.0.0 <= 8.1.11

Apache Traffic Server 9.0.0 <= 9.2.5

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.