Apache Traffic Server
cpe:2.3:a:apache:traffic_server:*:*:*:*:*:*:*
- >= 9.0.0, <= 9.2.13
- >= 10.0.0, <= 10.1.2
A denial-of-service vulnerability has been identified in Apache Traffic Server, specifically in the HTTP/2 protocol, where stalled flow-control can be exploited. This issue affects Apache Traffic Server versions 9.0.0 prior to 9.1.14 and 10.0.0 prior to 10.1.3.
Exploitation of this vulnerability leads to a denial-of-service condition by causing stalled flow-control in HTTP/2, which can disrupt normal traffic management and processing.
Users of Apache Traffic Server 9.x should upgrade to version 9.1.14 or later. Users of Apache Traffic Server 10.x should upgrade to version 10.1.3 or later.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.