VulnerabilityModified
CVE-2021-44040
Improper Input Validation vulnerability in request line parsing of Apache Traffic Server allows an attacker to send invalid requests.
HIGH 7.5EPSS 1.99%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.99%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Improper Input Validation vulnerability in request line parsing of Apache Traffic Server allows an attacker to send invalid requests. This issue affects Apache Traffic Server 8.0.0 to 8.1.3 and 9.0.0 to 9.1.1.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 1.99% probability · 80th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- apache/traffic server · debian/debian linux
- Source
- security@apache.org
References
- https://lists.apache.org/thread/zblwzcfs9ryhwjr89wz4osw55pxm6dx6Mailing List, Vendor Advisory
- https://www.debian.org/security/2022/dsa-5153Third Party Advisory
- https://lists.apache.org/thread/zblwzcfs9ryhwjr89wz4osw55pxm6dx6Mailing List, Vendor Advisory
- https://www.debian.org/security/2022/dsa-5153Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.