PT-2024-9752 · Apache+1 · Apache Traffic Control+1

Yuan Luo

·

Published

2024-08-28

·

Updated

2025-01-10

·

CVE-2024-45387

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache Traffic Control versions 8.0.0 through 8.0.1
Description A critical SQL injection vulnerability in Apache Traffic Control allows a privileged user with roles such as "admin", "federation", "operations", "portal", or "steering" to execute arbitrary SQL against the database by sending a specially crafted PUT request. This flaw can be easily exploited, potentially compromising sensitive data and disrupting critical services. It is estimated that over 365,000 services may be affected.
Recommendations Update to version 8.0.2 as soon as possible to patch the vulnerability. Audit access permissions for high-risk roles. Double-check database configurations for security loopholes.

Fix

Improper Authorization

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-11488
CVE-2024-45387
GHSA-VQ94-9PFV-CCQR
GO-2024-3358
OPENSUSE-SU-2025:14624-1
OPENSUSE-SU-2025_0060-1
SUSE-SU-2025:0060-1

Affected Products

Apache Traffic Control
Suse