PT-2023-28084 · Apache · Apache Traffic Server

Masakazu Kitajo

·

Publicado

2023-10-17

·

Atualizado

2025-06-12

·

CVE-2023-41752

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apache Traffic Server versions 8.0.0 through 8.1.8 Apache Traffic Server versions 9.0.0 through 9.2.2
Description The issue is related to the exposure of sensitive information to an unauthorized actor. It affects Apache Traffic Server, allowing unauthorized access to sensitive data.
Recommendations Apache Traffic Server versions 8.0.0 through 8.1.8 should be upgraded to version 8.1.9. Apache Traffic Server versions 9.0.0 through 9.2.2 should be upgraded to version 9.2.3.

Exploit

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-41752
DLA-3645-1
DSA-5549-1

Produtos afetados

Apache Traffic Server