Количество 4
Количество 4
CVE-2024-45387
An SQL injection vulnerability in Traffic Ops in Apache Traffic Control <= 8.0.1, >= 8.0.0 allows a privileged user with role "admin", "federation", "operations", "portal", or "steering" to execute arbitrary SQL against the database by sending a specially-crafted PUT request. Users are recommended to upgrade to version Apache Traffic Control 8.0.2 if you run an affected version of Traffic Ops.
GHSA-vq94-9pfv-ccqr
SQL injection in Apache Traffic Control
BDU:2024-11488
Уязвимость компонента PUT Request Handler системы построения CDN-сети Apache Traffic Control, позволяющая нарушителю выполнить произвольный код
SUSE-SU-2025:0060-1
Security update for govulncheck-vulndb
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2024-45387 An SQL injection vulnerability in Traffic Ops in Apache Traffic Control <= 8.0.1, >= 8.0.0 allows a privileged user with role "admin", "federation", "operations", "portal", or "steering" to execute arbitrary SQL against the database by sending a specially-crafted PUT request. Users are recommended to upgrade to version Apache Traffic Control 8.0.2 if you run an affected version of Traffic Ops. | CVSS3: 9.9 | 41% Средний | около 1 года назад | |
GHSA-vq94-9pfv-ccqr SQL injection in Apache Traffic Control | CVSS3: 8.8 | 41% Средний | около 1 года назад | |
BDU:2024-11488 Уязвимость компонента PUT Request Handler системы построения CDN-сети Apache Traffic Control, позволяющая нарушителю выполнить произвольный код | CVSS3: 9.9 | 41% Средний | больше 1 года назад | |
SUSE-SU-2025:0060-1 Security update for govulncheck-vulndb | около 1 года назад |
Уязвимостей на страницу