ATS negative cache option is vulnerable to a cache poisoning attack. If you have this option enabled, please upgrade or disable this feature. Apache Traffic Server versions 7.0.0 to 7.1.11 and 8.0.0 to 8.1.0 are affected.
References
Link | Resource |
---|---|
https://lists.apache.org/thread.html/raa9f0589c26c4d146646425e51e2a33e1457492df9f7ea2019daa6d3%40%3Cannounce.trafficserver.apache.org%3E | Mailing List Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2021-01-11 02:15
Updated : 2021-01-15 09:41
NVD link : CVE-2020-17509
Mitre link : CVE-2020-17509
JSON object : View
CWE
CWE-444
Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
Products Affected
apache
- traffic_server