Apache Traffic Server
cpe:2.3:a:apache:traffic_server:*:*:*:*:*:*:*
- >= 9.0.0, <= 9.2.8
- >= 10.0.0, <= 10.0.3
A vulnerability allowing request smuggling via pipelining after a chunked message body has been identified in Apache Traffic Server. This issue arises from improper input validation and affects versions 8.0.0 through 8.1.11, 9.0.0 through 9.2.8, and 10.0.0 through 10.0.3.
Exploitation of this vulnerability allows for request smuggling, which can disrupt the normal processing of requests and responses between a client and server, potentially leading to unauthorized access or manipulation of data.
Users of Apache Traffic Server 9.x should upgrade to version 9.2.9 or later. Users of Apache Traffic Server 10.x should upgrade to version 10.0.4 or later.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.