PT-2018-18399 · Apache · Apache Traffic Server

Published

2018-08-29

·

Updated

2019-10-03

·

CVE-2018-8040

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions: Apache Traffic Server (ATS) versions 6.0.0 through 6.2.2 Apache Traffic Server (ATS) versions 7.0.0 through 7.1.3
Description: The issue affects pages rendered using the ESI plugin, allowing access to the cookie header even when the plugin is configured to deny access.
Recommendations: For versions 6.0.0 through 6.2.2, upgrade to version 6.2.3 or later. For versions 7.0.0 through 7.1.3, upgrade to version 7.1.4 or later.

Fix

Exposure of Resource to Wrong Sphere

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-8040
DSA-4282-1

Affected Products

Apache Traffic Server