[ANNOUNCE] Apache Traffic Server is vulnerable to request smuggling and DoS
Masakazu Kitajo <[email protected]> Thu, 25 Jul 2024 10:01:15 -0600
| Newsgroups | gmane.comp.security.oss.general,gmane.comp.jakarta.avalon.user,gmane.comp.apache.maven.announce,gmane.comp.apache.incubator.ranger.devel |
|---|---|
| Message-ID | <CAGjw+kOARWH4mWz_RKe=oeSOkBZgfsUjTp2hM3X7FngdCaFc9w__31619.1370877036$1721924358$gmane$org@mail.gmail.com> |
--000000000000c9aad3061e1481a8 Content-Type: text/plain; charset="UTF-8" Description: Apache Traffic Server is vulnerable to request smuggling and DoS CVE: CVE-2023-38522 - Incomplete field name check allows request smuggling CVE-2024-35161 - Incomplete check for chunked trailer section allows request smuggling CVE-2024-35296 - Invalid Accept-Encoding can force forwarding requests Reported By: Ben Kallus (CVE-2023-38522) Keran Mu (CVE-2024-35161) Min Chen (CVE-2024-35296) Vendor: The Apache Software Foundation Version Affected: ATS 8.0.0 to 8.1.10 ATS 9.0.0 to 9.2.4 Mitigation: 8.x users should upgrade to 8.1.11 or later versions 9.x users should upgrade to 9.2.5 or later versions CVE: https://www.cve.org/CVERecord?id=CVE-2023-38522 https://www.cve.org/CVERecord?id=CVE-2024-35161 https://www.cve.org/CVERecord?id=CVE-2024-35296 -- Masakazu --000000000000c9aad3061e1481a8--