Improper Access Control in Apache Traffic Server by Apache
CVE-2024-56195

6.3MEDIUM

Key Information:

Vendor
Apache
Vendor
CVE Published:
6 March 2025

Badges

📰 News Worthy

Summary

An improper access control vulnerability has been identified in Apache Traffic Server, which can potentially allow unauthorized access to sensitive resources. This issue affects multiple versions of the product, specifically from 9.2.0 to 9.2.8 and from 10.0.0 to 10.0.3. Users of affected versions are strongly encouraged to upgrade to versions 9.2.9 or 10.0.4, which contain necessary fixes to mitigate this vulnerability. For further information and guidance, consult the Apache vendor advisory.

Affected Version(s)

Apache Traffic Server 9.2.0 <= 9.2.8

Apache Traffic Server 10.0.0 <= 10.0.3

News Articles

New Apache Traffic Server Flaws Allow Malformed Request Exploits

The Apache Software Foundation has disclosed several vulnerabilities affecting its Traffic Server software.

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • 📰

    First article discovered by GBHackers News

  • Vulnerability published

  • Vulnerability Reserved

Credit

Masaori Koshiba
.