Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2023-93321
HistoryOct 25, 2023 - 12:00 a.m.

Apache Traffic Server Input Validation Error Vulnerability (CNVD-2023-93321)

2023-10-2500:00:00
China National Vulnerability Database
www.cnvd.org.cn
20
apache traffic server
input validation
vulnerability
http/2
s3
authentication
denial of service

AI Score

7.1

Confidence

High

EPSS

0.002

Percentile

64.8%

Apache Traffic Server (ATS) is the United States Apache (Apache) Foundation’s set of scalable HTTP proxy and caching server. Apache Traffic Server suffers from an input validation error vulnerability that stems from an HTTP/2 frame formatting error and is vulnerable to HTTP/2 and s3 authentication plugin attacks. An attacker could exploit this vulnerability to cause a denial of service.

AI Score

7.1

Confidence

High

EPSS

0.002

Percentile

64.8%