PT-2021-10098 · Apache · Apache Traffic Control

Published

2021-01-26

·

Updated

2022-04-01

·

CVE-2020-17522

CVSS v3.1

5.8

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions: Apache Traffic Control versions 3.0.0 through 3.1.0 Apache Traffic Control versions 4.0.0 through 4.1.0
Description: The issue arises when ORT (now via atstccfg) generates ip allow.config files, including permissions that allow malicious actors to push arbitrary content into and remove arbitrary content from CDN cache servers. These permissions may also be extended to IP addresses outside the desired range, potentially granting them to clients outside the CDN architecture.
Recommendations: For versions 3.0.0 through 3.1.0, consider restricting access to the ip allow.config files to prevent unauthorized modifications. For versions 4.0.0 through 4.1.0, consider implementing additional security measures to limit the permissions granted to IP addresses, ensuring they are within the desired range. As a temporary workaround, consider disabling the generation of ip allow.config files via atstccfg until a patch is available.

Fix

Incorrect Permission

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-17522
GHSA-PW59-4QGF-JXR8

Affected Products

Apache Traffic Control