Vulnerabilities > Apache > Traffic Control > 2.1.0

DATE CVE VULNERABILITY TITLE RISK
2022-02-06 CVE-2022-23206 Server-Side Request Forgery (SSRF) vulnerability in Apache Traffic Control
In Apache Traffic Control Traffic Ops prior to 6.1.0 or 5.1.6, an unprivileged user who can reach Traffic Ops over HTTPS can send a specially-crafted POST request to /user/login/oauth to scan a port of a server that Traffic Ops can reach.
network
low complexity
apache CWE-918
5.0