Search CVE reports


Toggle filters

41 – 50 of 74 results


CVE-2021-32567

Medium priority
Vulnerable

Improper Input Validation vulnerability in HTTP/2 of Apache Traffic Server allows an attacker to DOS the server. This issue affects Apache Traffic Server 7.0.0 to 7.1.12, 8.0.0 to 8.1.1, 9.0.0 to 9.0.1.

1 affected package

trafficserver

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
trafficserver Vulnerable Vulnerable Vulnerable Needs evaluation
Show less packages

CVE-2021-32566

Medium priority
Vulnerable

Improper Input Validation vulnerability in HTTP/2 of Apache Traffic Server allows an attacker to DOS the server. This issue affects Apache Traffic Server 7.0.0 to 7.1.12, 8.0.0 to 8.1.1, 9.0.0 to 9.0.1.

1 affected package

trafficserver

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
trafficserver Vulnerable Vulnerable Vulnerable Needs evaluation
Show less packages

CVE-2021-32565

Medium priority
Vulnerable

Invalid values in the Content-Length header sent to Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache Traffic Server 7.0.0 to 7.1.12, 8.0.0 to 8.1.1, 9.0.0 to 9.0.1.

1 affected package

trafficserver

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
trafficserver Vulnerable Vulnerable Vulnerable Needs evaluation
Show less packages

CVE-2021-27737

Low priority
Needs evaluation

Apache Traffic Server 9.0.0 is vulnerable to a remote DOS attack on the experimental Slicer plugin.

1 affected package

trafficserver

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
trafficserver Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2021-27577

Medium priority
Vulnerable

Incorrect handling of url fragment vulnerability of Apache Traffic Server allows an attacker to poison the cache. This issue affects Apache Traffic Server 7.0.0 to 7.1.12, 8.0.0 to 8.1.1, 9.0.0 to 9.0.1.

1 affected package

trafficserver

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
trafficserver Vulnerable Vulnerable Vulnerable Needs evaluation
Show less packages

CVE-2020-9494

Medium priority
Vulnerable

Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.10, and 8.0.0 to 8.0.7 is vulnerable to certain types of HTTP/2 HEADERS frames that can cause the server to allocate a large amount of memory and spin the thread.

1 affected package

trafficserver

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
trafficserver Not affected Not affected Vulnerable Vulnerable
Show less packages

CVE-2020-9481

Medium priority
Needs evaluation

Apache ATS 6.0.0 to 6.2.3, 7.0.0 to 7.1.9, and 8.0.0 to 8.0.6 is vulnerable to a HTTP/2 slow read attack.

1 affected package

trafficserver

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
trafficserver Not affected Not affected Needs evaluation Needs evaluation
Show less packages

CVE-2020-1944

Medium priority
Needs evaluation

There is a vulnerability in Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.8, and 8.0.0 to 8.0.5 with a smuggling attack and Transfer-Encoding and Content length headers. Upgrade to versions 7.1.9 and 8.0.6 or later versions.

1 affected package

trafficserver

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
trafficserver Not affected Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2020-17509

Low priority
Vulnerable

ATS negative cache option is vulnerable to a cache poisoning attack. If you have this option enabled, please upgrade or disable this feature. Apache Traffic Server versions 7.0.0 to 7.1.11 and 8.0.0 to 8.1.0 are affected.

1 affected package

trafficserver

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
trafficserver Not affected Not affected Vulnerable Vulnerable
Show less packages

CVE-2020-17508

Low priority
Vulnerable

The ATS ESI plugin has a memory disclosure vulnerability. If you are running the plugin please upgrade. Apache Traffic Server versions 7.0.0 to 7.1.11 and 8.0.0 to 8.1.0 are affected.

1 affected package

trafficserver

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
trafficserver Not affected Not affected Vulnerable Vulnerable
Show less packages