VulnerabilityModified
CVE-2021-37148
Improper input validation vulnerability in header parsing of Apache Traffic Server allows an attacker to smuggle requests.
HIGH 7.5EPSS 2.59%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.59%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Improper input validation vulnerability in header parsing of Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache Traffic Server 8.0.0 to 8.1.2 and 9.0.0 to 9.0.1.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 2.59% probability · 84th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- apache/traffic server · debian/debian linux
- Source
- security@apache.org
References
- https://lists.apache.org/thread/k01797hyncx53659wr3o72s5cvkc3164Mailing List, Patch, Vendor Advisory
- https://www.debian.org/security/2022/dsa-5153Third Party Advisory
- https://lists.apache.org/thread/k01797hyncx53659wr3o72s5cvkc3164Mailing List, Patch, Vendor Advisory
- https://www.debian.org/security/2022/dsa-5153Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.