PT-2018-18399 · Apache · Apache Traffic Server
CVE-2018-8040
·
Publicado
2018-08-29
·
Atualizado
2019-10-03
CVSS v3.1
5.3
Média
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
Apache Traffic Server (ATS) versions 6.0.0 through 6.2.2
Apache Traffic Server (ATS) versions 7.0.0 through 7.1.3
Description:
The issue affects pages rendered using the ESI plugin, allowing access to the cookie header even when the plugin is configured to deny access.
Recommendations:
For versions 6.0.0 through 6.2.2, upgrade to version 6.2.3 or later.
For versions 7.0.0 through 7.1.3, upgrade to version 7.1.4 or later.
Correção
Exposure of Resource to Wrong Sphere
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Apache Traffic Server