PT-2023-4534 · Apache · Apache Traffic Server
Adi Peleg
+5
·
Published
2023-08-09
·
Updated
2024-10-01
·
CVE-2023-33934
CVSS v2.0
9.4
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
Apache Traffic Server versions through 9.2.1
Description
The issue is related to improper input validation in Apache Traffic Server, which can be exploited by a remote attacker to cause a denial of service.
Recommendations
For versions through 9.2.1, update to a version later than 9.2.1 to resolve the issue.
As a temporary workaround, consider restricting input validation to minimize the risk of exploitation.
Exploit
Fix
RCE
HTTP Request/Response Smuggling
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Apache Traffic Server