Improper Authorization in Apache Traffic Server - CVE-2021-37150

 

Improper Authorization in Apache Traffic Server - CVE-2021-37150

Published: August 15, 2022


Vulnerability identifier: #VU66504
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-37150
CWE-ID: CWE-285
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to an error when handling different protocols and schemes. A remote attacker can send a specially crafted HTTP request, bypass implemented security restrictions and gain access unauthorized access to protected resources.


Affected software

Apache Traffic Server
Debian Linux
Fedora
trafficserver (Debian package)
trafficserver

How to mitigate CVE-2021-37150

Install updates from vendor's website.

Apache Traffic Server - addressed in versions 8.1.5, 9.1.3
trafficserver (Debian package) - update to 8.1.5+ds-1~deb11u1
trafficserver - addressed in versions 9.1.3-1.el7, 9.1.3-1.el8, 9.1.3-1.el9, 9.1.3-1.fc35, 9.1.3-1.fc36

External References

Related Security Bulletins