Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-38479

Опубликовано: 14 нояб. 2024
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

Improper Input Validation vulnerability in Apache Traffic Server.

This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.5.

Users are recommended to upgrade to version 9.2.6, which fixes the issue, or 10.0.2, which does not have the issue.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:apache:traffic_server:*:*:*:*:*:*:*:*
Версия от 8.0.0 (включая) до 8.1.11 (включая)
cpe:2.3:a:apache:traffic_server:*:-:*:*:*:*:*:*
Версия от 9.0.0 (включая) до 9.2.6 (исключая)

EPSS

Процентиль: 55%
0.00324
Низкий

7.5 High

CVSS3

Дефекты

CWE-20
NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 1 года назад

Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.5. Users are recommended to upgrade to version 9.2.6, which fixes the issue, or 10.0.2, which does not have the issue.

CVSS3: 7.5
debian
около 1 года назад

Improper Input Validation vulnerability in Apache Traffic Server. Thi ...

CVSS3: 7.5
github
около 1 года назад

Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.5. Users are recommended to upgrade to version 9.2.6, which fixes the issue, or 10.0.2, which does not have the issue.

CVSS3: 7.5
fstec
около 1 года назад

Уязвимость плагина Cache Key Manipulation Plugin веб-сервера Apache Traffic Server, позволяющая нарушителю реализовать атаку отравления кэша

EPSS

Процентиль: 55%
0.00324
Низкий

7.5 High

CVSS3

Дефекты

CWE-20
NVD-CWE-noinfo