4.3
CVE-2024-56202
- EPSS 0.14%
- Veröffentlicht 06.03.2025 11:15:11
- Zuletzt bearbeitet 29.04.2025 16:41:26
- Quelle security@apache.org
- CVE-Watchlists
- Unerledigt
Apache Traffic Server: Expect header field can unreasonably retain resource
Expected Behavior Violation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.0.0 through 9.2.8, from 10.0.0 through 10.0.3. Users are recommended to upgrade to versions 9.2.9 or 10.0.4 or newer, which fixes the issue.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Apache ≫ Traffic Server Version >= 9.0.0 < 9.2.9
Apache ≫ Traffic Server Version >= 10.0.0 < 10.0.4
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.14% | 0.339 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 4.3 | 2.8 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
|
CWE-440 Expected Behavior Violation
A feature, API, or function does not perform according to its specification.