| Vulnerability Name: | CVE-2021-44040 (CCN-222446) | ||||||||||||
| Assigned: | 2021-11-19 | ||||||||||||
| Published: | 2022-03-23 | ||||||||||||
| Updated: | 2022-10-14 | ||||||||||||
| Summary: | Improper Input Validation vulnerability in request line parsing of Apache Traffic Server allows an attacker to send invalid requests. This issue affects Apache Traffic Server 8.0.0 to 8.1.3 and 9.0.0 to 9.1.1. | ||||||||||||
| CVSS v3 Severity: | 7.5 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N) 6.5 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C)
4.6 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C)
| ||||||||||||
| CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N)
| ||||||||||||
| Vulnerability Type: | CWE-20 | ||||||||||||
| Vulnerability Consequences: | Bypass Security | ||||||||||||
| References: | Source: MITRE Type: CNA CVE-2021-44040 Source: XF Type: UNKNOWN apache-cve202144040-sec-bypass(222446) Source: CCN Type: Apache Mailing List, Wednesday, March 23, 2022 9:34:14 AM EDT Apache Traffic Server is vulnerable to potential smuggle and MITM attacks Source: CONFIRM Type: Mailing List, Vendor Advisory N/A Source: CCN Type: Apache Web site Traffic Server Source: DEBIAN Type: Third Party Advisory DSA-5153 | ||||||||||||
| Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||
| BACK | |||||||||||||