PT-2023-3286 · Apache · Apache Traffic Server

Chris Lemmons

·

Publicado

2023-06-13

·

Atualizado

2024-02-01

·

CVE-2023-30631

CVSS v2.0

7.8

Alta

VetorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Apache Traffic Server versions 8.0.0 through 9.2.0
Description The issue is related to improper input validation in Apache Traffic Server. The configuration option proxy.config.http.push method enabled did not function as expected. However, by default, the PUSH method is blocked in the ip allow configuration file. This could potentially allow a remote attacker to cause a denial of service.
Recommendations 8.x users should upgrade to 8.1.7 or later versions 9.x users should upgrade to 9.2.1 or later versions

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-03423
CVE-2023-30631
DLA-3475-1
DSA-5435-1
DSA-5435-2

Produtos afetados

Apache Traffic Server