Input validation error in Apache Traffic Server - CVE-2020-17509
Published: December 8, 2020
Vulnerability identifier: #VU48817
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-17509
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform cache poisoning attacks.
The vulnerability exists due to insufficient validation of user-supplied input in Apache Traffic Server when negative cache option is enabled. A remote attacker can send specially crafted data to the proxy server and poison negative server's cache.
Affected software
Apache Traffic Server
trafficserver (Debian package)
trafficserver (Debian package)
How to mitigate CVE-2020-17509
Install updates from vendor's website.
Apache Traffic Server - addressed in versions 7.1.11, 8.0.8
trafficserver (Debian package) - update to 8.0.2+ds-1+deb10u4
trafficserver (Debian package) - update to 8.0.2+ds-1+deb10u4