Apache

Traffic Control

7 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 32.36%
  • Published 23.12.2024 16:15:06
  • Last modified 11.02.2025 16:07:15

An SQL injection vulnerability in Traffic Ops in Apache Traffic Control <= 8.0.1, >= 8.0.0 allows a privileged user with role "admin", "federation", "operations", "portal", or "steering" to execute arbitrary SQL against the database by sending a spec...

  • EPSS 0.87%
  • Published 06.02.2022 16:15:07
  • Last modified 21.11.2024 06:48:12

In Apache Traffic Control Traffic Ops prior to 6.1.0 or 5.1.6, an unprivileged user who can reach Traffic Ops over HTTPS can send a specially-crafted POST request to /user/login/oauth to scan a port of a server that Traffic Ops can reach.

  • EPSS 2.87%
  • Published 11.11.2021 13:15:07
  • Last modified 21.11.2024 06:29:07

An unauthenticated Apache Traffic Control Traffic Ops user can send a request with a specially-crafted username to the POST /login endpoint of any API version to inject unsanitized content into the LDAP filter.

  • EPSS 0.65%
  • Published 12.10.2021 08:15:06
  • Last modified 21.11.2024 06:27:03

An authenticated Apache Traffic Control Traffic Ops user with Portal-level privileges can send a request with a specially-crafted email subject to the /deliveryservices/request Traffic Ops endpoint to send an email, from the Traffic Ops server, with ...

  • EPSS 2.16%
  • Published 26.01.2021 18:15:40
  • Last modified 21.11.2024 05:08:17

When ORT (now via atstccfg) generates ip_allow.config files in Apache Traffic Control 3.0.0 to 3.1.0 and 4.0.0 to 4.1.0, those files include permissions that allow bad actors to push arbitrary content into and remove arbitrary content from CDN cache ...

  • EPSS 1.17%
  • Published 09.09.2019 17:15:13
  • Last modified 21.11.2024 04:22:46

Improper authentication is possible in Apache Traffic Control versions 3.0.0 and 3.0.1 if LDAP is enabled for login in the Traffic Ops API component. Given a username for a user that can be authenticated via LDAP, it is possible to improperly authent...

  • EPSS 1.28%
  • Published 10.07.2017 18:29:00
  • Last modified 20.04.2025 01:37:25

The Traffic Router component of the incubating Apache Traffic Control project is vulnerable to a Slowloris style Denial of Service attack. TCP connections made on the configured DNS port will remain in the ESTABLISHED state until the client explicitl...