Configuration in Apache Traffic Server - CVE-2023-30631
Published: August 21, 2023
Vulnerability identifier: #VU79780
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-30631
CWE-ID: CWE-16
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The issue may allow a remote attacker to bypass implemented security restrictions.
The issue exists due to the configuration option proxy.config.http.push_method_enabled does not work. A remote attacker can still use the PUSH method to send data to the application.
Affected software
Apache Traffic Server
Debian Linux
Fedora
trafficserver (Debian package)
trafficserver
Debian Linux
Fedora
trafficserver (Debian package)
trafficserver
How to mitigate CVE-2023-30631
Install updates from vendor's website.
Apache Traffic Server - addressed in versions 8.1.7, 9.2.1
trafficserver (Debian package) - addressed in versions 8.1.7+ds-1~deb11u1, 9.2.0+ds-1~deb12u1
trafficserver - addressed in versions 9.2.1-1.el7, 9.2.1-1.el8, 9.2.1-1.el9, 9.2.1-1.fc37, 9.2.1-1.fc38
trafficserver (Debian package) - addressed in versions 8.1.7+ds-1~deb11u1, 9.2.0+ds-1~deb12u1
trafficserver - addressed in versions 9.2.1-1.el7, 9.2.1-1.el8, 9.2.1-1.el9, 9.2.1-1.fc37, 9.2.1-1.fc38
External References
- https://lists.apache.org/thread/tns2b4khyyncgs5v5p9y35pobg9z2bvs
- https://www.debian.org/security/2023/dsa-5435
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6GDCBNFDDW6ULW7CACJCPENI7BVDHM5O/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FGWXNAEEVRUZ5JG4EJAIIFC3CI7LFETV/
- https://lists.debian.org/debian-lts-announce/2023/06/msg00037.html