Apache Traffic Server PROXY Protocol ACL Bypass Vulnerability

Vulnerability

A vulnerability exists in Apache Traffic Server (ATS) versions 9.0.0 through 9.2.10 and 10.0.0 through 10.0.5, where the Access Control List (ACL) does not properly utilize IP addresses provided by the PROXY protocol. This can lead to unintended access control behavior. Users can configure which IP addresses to use for ACLs by setting 'proxy.config.acl.subjects' when PROXY protocol is enabled. The issue arises because the default behavior does not account for PROXY protocol headers, potentially allowing unauthorized access or actions.

Impact

Exploitation of this vulnerability can result in improper ACL enforcement, allowing clients to bypass intended access controls based on IP addresses.

Remediation

Users of Apache Traffic Server should upgrade to version 9.2.11 or 10.0.6. After upgrading, those who use the PROXY protocol must configure the 'proxy.config.acl.subjects' setting to ensure proper ACL functionality. For users of the ESI plugin, the '--max-inclusion-depth' setting can be adjusted to prevent memory exhaustion issues.

Added: Jun 19, 2025, 10:22 AM
Updated: Jun 19, 2025, 10:22 AM

Vulnerability Rating

Custom Algorithm
spread
5.2
impact
5.0
exploitability
7.6
remediation
8.3
relevance
0.2
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.