Input validation error in Apache Traffic Server - CVE-2024-35161
Published: August 12, 2024
Vulnerability identifier: #VU95787
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-35161
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to the affected application forwards malformed HTTP chunked trailer section to origin servers. A remote attacker can perform the request smuggling and cache poisoning attacks.
Affected software
Apache Traffic Server
Debian Linux
Fedora
trafficserver (Debian package)
trafficserver
Debian Linux
Fedora
trafficserver (Debian package)
trafficserver
How to mitigate CVE-2024-35161
Install updates from vendor's website.
Apache Traffic Server - addressed in versions 8.1.11, 9.2.5
trafficserver (Debian package) - update to 9.2.5+ds-0+deb12u1
trafficserver - addressed in versions 9.2.5-1.el8, 9.2.5-1.el9, 9.2.5-1.fc39, 9.2.5-1.fc40
trafficserver (Debian package) - update to 9.2.5+ds-0+deb12u1
trafficserver - addressed in versions 9.2.5-1.el8, 9.2.5-1.el9, 9.2.5-1.fc39, 9.2.5-1.fc40