Lucene search

K
cvelistApacheCVELIST:CVE-2021-37148
HistoryNov 03, 2021 - 3:20 p.m.

CVE-2021-37148 Request Smuggling - transfer encoding validation

2021-11-0315:20:20
CWE-20
apache
www.cve.org
6
cve-2021-37148
request smuggling
header parsing
apache traffic server
transfer encoding validation

AI Score

7.9

Confidence

High

EPSS

0.002

Percentile

55.5%

Improper input validation vulnerability in header parsing of Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache Traffic Server 8.0.0 to 8.1.2 and 9.0.0 to 9.0.1.

CNA Affected

[
  {
    "product": "Apache Traffic Server",
    "vendor": "Apache Software Foundation",
    "versions": [
      {
        "status": "affected",
        "version": "8.0.0 to 8.1.2 and 9.0.0 to 9.0.1"
      }
    ]
  }
]

AI Score

7.9

Confidence

High

EPSS

0.002

Percentile

55.5%