Lucene search

K
cvelistApacheCVELIST:CVE-2021-37147
HistoryNov 03, 2021 - 3:20 p.m.

CVE-2021-37147 Request Smuggling - LF line ending

2021-11-0315:20:19
CWE-444
CWE-20
apache
www.cve.org
7
cve-2021-37147
request smuggling
lf line ending
apache traffic server 8.0
apache traffic server 8.1.2
apache traffic server 9.0.0
apache traffic server 9.1.0
header parsing

AI Score

7.9

Confidence

High

EPSS

0.002

Percentile

55.9%

Improper input validation vulnerability in header parsing of Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache Traffic Server 8.0.0 to 8.1.2 and 9.0.0 to 9.1.0.

CNA Affected

[
  {
    "product": "Apache Traffic Server",
    "vendor": "Apache Software Foundation",
    "versions": [
      {
        "status": "affected",
        "version": "8.0.0 to 8.1.2 and 9.0.0 to 9.1.0"
      }
    ]
  }
]

AI Score

7.9

Confidence

High

EPSS

0.002

Percentile

55.9%