Логотип exploitDog
bind:CVE-2020-17522
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-17522

Количество 2

Количество 2

nvd логотип

CVE-2020-17522

около 5 лет назад

When ORT (now via atstccfg) generates ip_allow.config files in Apache Traffic Control 3.0.0 to 3.1.0 and 4.0.0 to 4.1.0, those files include permissions that allow bad actors to push arbitrary content into and remove arbitrary content from CDN cache servers. Additionally, these permissions are potentially extended to IP addresses outside the desired range, resulting in them being granted to clients possibly outside the CDN arcitechture.

CVSS3: 5.8
EPSS: Низкий
github логотип

GHSA-pw59-4qgf-jxr8

больше 4 лет назад

Cache Manipulation Attack in Apache Traffic Control

CVSS3: 5.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2020-17522

When ORT (now via atstccfg) generates ip_allow.config files in Apache Traffic Control 3.0.0 to 3.1.0 and 4.0.0 to 4.1.0, those files include permissions that allow bad actors to push arbitrary content into and remove arbitrary content from CDN cache servers. Additionally, these permissions are potentially extended to IP addresses outside the desired range, resulting in them being granted to clients possibly outside the CDN arcitechture.

CVSS3: 5.8
2%
Низкий
около 5 лет назад
github логотип
GHSA-pw59-4qgf-jxr8

Cache Manipulation Attack in Apache Traffic Control

CVSS3: 5.8
2%
Низкий
больше 4 лет назад

Уязвимостей на страницу