Incorrect handling of url fragment vulnerability of Apache Traffic Server allows an attacker to poison the cache. This issue affects Apache Traffic Server 7.0.0 to 7.1.12, 8.0.0 to 8.1.1, 9.0.0 to 9.0.1.
2021-06-29T12:15:08.437
2024-11-21T05:58:13.510
Modified
CVSSv3.1: 7.5 (HIGH)
AV:N/AC:L/Au:N/C:N/I:P/A:N
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | apache | traffic_server | ≤ 7.1.12 | Yes |
Application | apache | traffic_server | ≤ 8.1.1 | Yes |
Application | apache | traffic_server | ≤ 9.0.1 | Yes |
Operating System | debian | debian_linux | 8.0 | Yes |