Input validation error in Apache Traffic Server - CVE-2023-38522

 

Input validation error in Apache Traffic Server - CVE-2023-38522

Published: August 12, 2024


Vulnerability identifier: #VU95786
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-38522
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise the target system.

The vulnerability exists due to the affected application accepts characters that are not allowed for HTTP field names and forwards malformed requests to origin servers. A remote attacker can perform the request smuggling and cache poisoning attacks.


Affected software

Apache Traffic Server
Debian Linux
Fedora
trafficserver (Debian package)
trafficserver

How to mitigate CVE-2023-38522

Install updates from vendor's website.

Apache Traffic Server - addressed in versions 8.1.11, 9.2.5
trafficserver (Debian package) - update to 9.2.5+ds-0+deb12u1
trafficserver - addressed in versions 9.2.5-1.el8, 9.2.5-1.el9, 9.2.5-1.fc39, 9.2.5-1.fc40

External References

Related Security Bulletins