PT-2021-3576 · Apache · Apache Traffic Server

Iustin Ladunca

·

Published

2021-06-24

·

Updated

2021-12-23

·

CVE-2021-27577

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions Apache Traffic Server versions 7.0.0 through 7.1.12 Apache Traffic Server versions 8.0.0 through 8.1.1 Apache Traffic Server versions 9.0.0 through 9.0.1
Description The issue is related to the incorrect handling of the URL fragment in Apache Traffic Server, which allows an attacker to poison the cache. This can potentially impact the integrity of protected information. The vulnerability has been exploited in various real-world attacks, including cache poisoning attacks on different platforms.
Recommendations For Apache Traffic Server versions 7.0.0 through 7.1.12, update to a version outside of this range to resolve the issue. For Apache Traffic Server versions 8.0.0 through 8.1.1, update to a version outside of this range to resolve the issue. For Apache Traffic Server versions 9.0.0 through 9.0.1, update to a version outside of this range to resolve the issue. As a temporary workaround, consider restricting access to the cache to minimize the risk of exploitation.

Fix

HTTP Request/Response Smuggling

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-03677
CVE-2021-27577
DSA-4957-1

Affected Products

Apache Traffic Server