SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2018-8004

There are multiple HTTP smuggling and cache poisoning issues when clients making malicious requests interact with Apache Traffic Server (ATS).

MEDIUM 6.5EPSS 6.31%

Does this matter?

Lower severity and a low EPSS score (6.31%). Track it; it rarely justifies an emergency change on its own.

Description

There are multiple HTTP smuggling and cache poisoning issues when clients making malicious requests interact with Apache Traffic Server (ATS). This affects versions 6.0.0 to 6.2.2 and 7.0.0 to 7.1.3. To resolve this issue users running 6.x should upgrade to 6.2.3 or later versions and 7.x users should upgrade to 7.1.4 or later versions.

CVSS 3.0
6.5 MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
EPSS
6.31% probability · 93th percentile
CISA KEV
Not listed
Weakness
CWE-444
Affected
apache/traffic server · debian/debian linux
Source
security@apache.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.