Lucene search

K
cvelistApacheCVELIST:CVE-2021-44040
HistoryMar 23, 2022 - 2:05 p.m.

CVE-2021-44040 HTTP request line fuzzing attacks

2022-03-2314:05:15
CWE-20
apache
www.cve.org
6
cve-2021-44040
http request
input validation
apache traffic server

AI Score

7.9

Confidence

High

EPSS

0.002

Percentile

52.0%

Improper Input Validation vulnerability in request line parsing of Apache Traffic Server allows an attacker to send invalid requests. This issue affects Apache Traffic Server 8.0.0 to 8.1.3 and 9.0.0 to 9.1.1.

CNA Affected

[
  {
    "product": "Apache Traffic Server",
    "vendor": "Apache Software Foundation",
    "versions": [
      {
        "status": "affected",
        "version": "8.0.0 to 8.1.3 and 9.0.0 to 9.1.1"
      }
    ]
  }
]

AI Score

7.9

Confidence

High

EPSS

0.002

Percentile

52.0%