Lucene search

K
vulnrichmentApacheVULNRICHMENT:CVE-2023-41752
HistoryOct 17, 2023 - 6:57 a.m.

CVE-2023-41752 Apache Traffic Server: s3_auth plugin problem with hash calculation

2023-10-1706:57:47
CWE-200
apache
github.com
1
apache traffic server
s3_auth plugin
hash calculation
vulnerability
sensitive information exposure
unauthorized actor
upgrade
version 8.1.9
version 9.2.3

AI Score

6.7

Confidence

Low

SSVC

Exploitation

none

Automatable

yes

Technical Impact

partial

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Traffic Server.This issue affects Apache Traffic Server: from 8.0.0 through 8.1.8, from 9.0.0 through 9.2.2.

Users are recommended to upgrade to version 8.1.9 or 9.2.3, which fixes the issue.

ADP Affected

[
  {
    "cpes": [
      "cpe:2.3:a:apache_software_foundation:apache_traffic_server:*:*:*:*:*:*:*:*"
    ],
    "vendor": "apache_software_foundation",
    "product": "apache_traffic_server",
    "versions": [
      {
        "status": "affected",
        "version": "8.0.0",
        "versionType": "custom",
        "lessThanOrEqual": "8.1.8"
      },
      {
        "status": "affected",
        "version": "9.0.0",
        "versionType": "custom",
        "lessThanOrEqual": "9.2.2"
      }
    ],
    "defaultStatus": "unknown"
  }
]

AI Score

6.7

Confidence

Low

SSVC

Exploitation

none

Automatable

yes

Technical Impact

partial