Vulnerabilities > Apache > Traffic Control > 1.1.2

DATE CVE VULNERABILITY TITLE RISK
2022-02-06 CVE-2022-23206 Server-Side Request Forgery (SSRF) vulnerability in Apache Traffic Control
In Apache Traffic Control Traffic Ops prior to 6.1.0 or 5.1.6, an unprivileged user who can reach Traffic Ops over HTTPS can send a specially-crafted POST request to /user/login/oauth to scan a port of a server that Traffic Ops can reach.
network
low complexity
apache CWE-918
5.0
2017-07-10 CVE-2017-7670 Resource Exhaustion vulnerability in Apache Traffic Control
The Traffic Router component of the incubating Apache Traffic Control project is vulnerable to a Slowloris style Denial of Service attack.
network
low complexity
apache CWE-400
7.5