PT-2021-3573 · Apache · Apache Traffic Server

Katsutoshi Ikenoya

·

Published

2021-06-24

·

Updated

2021-09-20

·

CVE-2021-32566

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Apache Traffic Server versions 7.0.0 through 7.1.12 Apache Traffic Server versions 8.0.0 through 8.1.1 Apache Traffic Server versions 9.0.0 through 9.0.1
Description The issue is caused by improper input validation in the HTTP/2 component of Apache Traffic Server. This allows a remote attacker to cause a denial of service.
Recommendations For Apache Traffic Server versions 7.0.0 through 7.1.12, update to a version outside of this range to resolve the issue. For Apache Traffic Server versions 8.0.0 through 8.1.1, update to a version outside of this range to resolve the issue. For Apache Traffic Server versions 9.0.0 through 9.0.1, update to a version outside of this range to resolve the issue. As a temporary workaround, consider restricting access to the HTTP/2 component until a patch is available.

Fix

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-03674
CVE-2021-32566
DSA-4957-1

Affected Products

Apache Traffic Server