Improper Authorization in Apache Traffic Server - CVE-2021-37150
Published: August 15, 2022
Vulnerability identifier: #VU66504
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-37150
CWE-ID: CWE-285
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to gain access to sensitive information.
The
vulnerability exists due to an error when handling different protocols and schemes. A remote attacker can send a specially crafted HTTP request, bypass implemented security restrictions and gain access unauthorized access to protected resources.
Affected software
Apache Traffic Server
Debian Linux
Fedora
trafficserver (Debian package)
trafficserver
Debian Linux
Fedora
trafficserver (Debian package)
trafficserver
How to mitigate CVE-2021-37150
Install updates from vendor's website.
Apache Traffic Server - addressed in versions 8.1.5, 9.1.3
trafficserver (Debian package) - update to 8.1.5+ds-1~deb11u1
trafficserver - addressed in versions 9.1.3-1.el7, 9.1.3-1.el8, 9.1.3-1.el9, 9.1.3-1.fc35, 9.1.3-1.fc36
trafficserver (Debian package) - update to 8.1.5+ds-1~deb11u1
trafficserver - addressed in versions 9.1.3-1.el7, 9.1.3-1.el8, 9.1.3-1.el9, 9.1.3-1.fc35, 9.1.3-1.fc36