| Vulnerability Name: | CVE-2018-11783 (CCN-156957) | ||||||||||||||||||||||||||||||||||||
| Assigned: | 2018-06-05 | ||||||||||||||||||||||||||||||||||||
| Published: | 2019-02-12 | ||||||||||||||||||||||||||||||||||||
| Updated: | 2019-03-18 | ||||||||||||||||||||||||||||||||||||
| Summary: | sslheaders plugin extracts information from the client certificate and sets headers in the request based on the configuration of the plugin. The plugin doesn't strip the headers from the request in some scenarios. This problem was discovered in versions 6.0.0 to 6.0.3, 7.0.0 to 7.1.5, and 8.0.0 to 8.0.1. | ||||||||||||||||||||||||||||||||||||
| CVSS v3 Severity: | 7.5 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N) 6.5 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C)
4.6 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C)
| ||||||||||||||||||||||||||||||||||||
| CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)
| ||||||||||||||||||||||||||||||||||||
| Vulnerability Type: | CWE-200 | ||||||||||||||||||||||||||||||||||||
| Vulnerability Consequences: | Gain Access | ||||||||||||||||||||||||||||||||||||
| References: | Source: MITRE Type: CNA CVE-2018-11783 Source: CCN Type: Apache Web site Traffic Server Source: BID Type: Third Party Advisory 107032 Source: XF Type: UNKNOWN apache-cve201811783-unspecified(156957) Source: CCN Type: trafficserver GIT Repository Make sslheaders plugin better conform to documentation. #4701 Source: MLIST Type: Mailing List, Third Party Advisory [trafficserver-announce] 20190212 [ANNOUNCE] Apache Traffic Server vulnerability with sslheader plugin Source: CCN Type: oss-sec Mailing List, Tue, 12 Feb 2019 15:42:35 -0800 [CVE-2018-11783] Apache Traffic Server vulnerability with sslheader plugin Source: CCN Type: WhiteSource Vulnerability Database CVE-2018-11783 | ||||||||||||||||||||||||||||||||||||
| Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||||||||||||||||||||||
| Oval Definitions | |||||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||||
| BACK | |||||||||||||||||||||||||||||||||||||