PT-2021-10098 · Apache · Apache Traffic Control
Published
2021-01-26
·
Updated
2022-04-01
·
CVE-2020-17522
CVSS v3.1
5.8
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
Apache Traffic Control versions 3.0.0 through 3.1.0
Apache Traffic Control versions 4.0.0 through 4.1.0
Description:
The issue arises when ORT (now via atstccfg) generates ip allow.config files, including permissions that allow malicious actors to push arbitrary content into and remove arbitrary content from CDN cache servers. These permissions may also be extended to IP addresses outside the desired range, potentially granting them to clients outside the CDN architecture.
Recommendations:
For versions 3.0.0 through 3.1.0, consider restricting access to the ip allow.config files to prevent unauthorized modifications.
For versions 4.0.0 through 4.1.0, consider implementing additional security measures to limit the permissions granted to IP addresses, ensuring they are within the desired range.
As a temporary workaround, consider disabling the generation of ip allow.config files via atstccfg until a patch is available.
Fix
Incorrect Permission
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Apache Traffic Control