CVE-2021-27577

Incorrect handling of url fragment vulnerability of Apache Traffic Server allows an attacker to poison the cache. This issue affects Apache Traffic Server 7.0.0 to 7.1.12, 8.0.0 to 8.1.1, 9.0.0 to 9.0.1.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:apache:traffic_server:*:*:*:*:*:*:*:*
cpe:2.3:a:apache:traffic_server:*:*:*:*:*:*:*:*
cpe:2.3:a:apache:traffic_server:*:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*

History

20 Sep 2021, 18:52

Type Values Removed Values Added
CPE cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
References
  • (DEBIAN) https://www.debian.org/security/2021/dsa-4957 - Third Party Advisory

06 Jul 2021, 15:28

Type Values Removed Values Added
CPE cpe:2.3:a:apache:traffic_server:*:*:*:*:*:*:*:*
CWE CWE-444
References (MISC) https://lists.apache.org/thread.html/ra1a41ff92a70d25bf576d7da2590575e8ff430393a3f4a0c34de4277%40%3Cusers.trafficserver.apache.org%3E - (MISC) https://lists.apache.org/thread.html/ra1a41ff92a70d25bf576d7da2590575e8ff430393a3f4a0c34de4277%40%3Cusers.trafficserver.apache.org%3E - Mailing List, Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : 5.0
v3 : 7.5

29 Jun 2021, 12:30

Type Values Removed Values Added
New CVE

Information

Published : 2021-06-29 12:15

Updated : 2023-12-10 13:55


NVD link : CVE-2021-27577

Mitre link : CVE-2021-27577

CVE.ORG link : CVE-2021-27577


JSON object : View

Products Affected

debian

  • debian_linux

apache

  • traffic_server
CWE
CWE-444

Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')