PT-2022-25505 · Apache · Apache Traffic Server

Nick Frost

·

Published

2022-12-19

·

Updated

2023-07-17

·

CVE-2022-40743

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Apache Traffic Server versions 9.0.0 through 9.1.3
Description The issue is related to an Improper Input Validation vulnerability for the xdebug plugin in Apache Software Foundation Apache Traffic Server, which can lead to cross site scripting and cache poisoning attacks.
Recommendations For Apache Traffic Server versions 9.0.0 through 9.1.3, users should upgrade to 9.1.4 or later versions.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2022-40743
OESA-2022-2164
OESA-2022-2166

Affected Products

Apache Traffic Server