Vulnerabilities > CVE-2021-37150
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
HIGH Integrity impact
NONE Availability impact
NONE Summary
Improper Input Validation vulnerability in header parsing of Apache Traffic Server allows an attacker to request secure resources. This issue affects Apache Traffic Server 8.0.0 to 9.1.2.
Vulnerable Configurations
References
- https://lists.apache.org/thread/rc64lwbdgrkv674koc3zl1sljr9vwg21
- https://lists.apache.org/thread/rc64lwbdgrkv674koc3zl1sljr9vwg21
- https://lists.debian.org/debian-lts-announce/2023/01/msg00019.html
- https://lists.debian.org/debian-lts-announce/2023/01/msg00019.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CJ67IWD5PRJUOIYIDJRUG3UMS2UF4X4J/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CJ67IWD5PRJUOIYIDJRUG3UMS2UF4X4J/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZCSBQBYPOZSWS5LCOAQ6LJLRLXFIAW5A/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZCSBQBYPOZSWS5LCOAQ6LJLRLXFIAW5A/
- https://www.debian.org/security/2022/dsa-5206
- https://www.debian.org/security/2022/dsa-5206