Vulnerabilities > Apache > Traffic Server > 7.1.1
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2019-08-13 | CVE-2019-9512 | Resource Exhaustion vulnerability in multiple products Some HTTP/2 implementations are vulnerable to ping floods, potentially leading to a denial of service. | 7.5 |
2019-08-13 | CVE-2019-9511 | Allocation of Resources Without Limits or Throttling vulnerability in multiple products Some HTTP/2 implementations are vulnerable to window size manipulation and stream prioritization manipulation, potentially leading to a denial of service. | 7.5 |
2019-03-07 | CVE-2018-11783 | Information Exposure vulnerability in Apache Traffic Server sslheaders plugin extracts information from the client certificate and sets headers in the request based on the configuration of the plugin. | 7.5 |
2018-08-29 | CVE-2018-8040 | Exposure of Resource to Wrong Sphere vulnerability in multiple products Pages that are rendered using the ESI plugin can have access to the cookie header when the plugin is configured not to allow access. | 5.3 |
2018-08-29 | CVE-2018-8005 | Resource Exhaustion vulnerability in multiple products When there are multiple ranges in a range request, Apache Traffic Server (ATS) will read the entire object from cache. | 5.3 |
2018-08-29 | CVE-2018-8004 | HTTP Request Smuggling vulnerability in multiple products There are multiple HTTP smuggling and cache poisoning issues when clients making malicious requests interact with Apache Traffic Server (ATS). | 6.5 |
2018-08-29 | CVE-2018-1318 | Improper Input Validation vulnerability in multiple products Adding method ACLs in remap.config can cause a segfault when the user makes a carefully crafted request. | 7.5 |