VulnerabilityModified
CVE-2022-37392
Improper Check for Unusual or Exceptional Conditions vulnerability in handling the requests to Apache Traffic Server.
MEDIUM 5.3EPSS 1.10%
Does this matter?
Lower severity and a low EPSS score (1.10%). Track it; it rarely justifies an emergency change on its own.
Description
Improper Check for Unusual or Exceptional Conditions vulnerability in handling the requests to Apache Traffic Server. This issue affects Apache Traffic Server 8.0.0 to 9.1.2.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 1.10% probability · 64th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-754
- Affected
- apache/traffic server
- Source
- security@apache.org
References
- https://lists.apache.org/thread/mrj2lg4s0hf027rk7gz8t7hbn9xpfg02Mailing List, Vendor Advisory
- https://lists.apache.org/thread/mrj2lg4s0hf027rk7gz8t7hbn9xpfg02Mailing List, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.