Apache Traffic Server 5.1.x before 5.1.1 allows remote attackers to bypass access restrictions by leveraging failure to properly tunnel remap requests using CONNECT.
References
Link | Resource |
---|---|
https://issues.apache.org/jira/browse/TS-2677 | Issue Tracking Patch Vendor Advisory |
http://mail-archives.apache.org/mod_mbox/www-announce/201411.mbox/%3C20141101231749.2E3561043F@minotaur.apache.org%3E | Issue Tracking Vendor Advisory |
http://www.securityfocus.com/bid/101630 | Third Party Advisory VDB Entry |
Configurations
Information
Published : 2017-10-30 07:29
Updated : 2017-11-17 10:20
NVD link : CVE-2014-3624
Mitre link : CVE-2014-3624
JSON object : View
CWE
CWE-284
Improper Access Control
Products Affected
apache
- traffic_server