UBUNTU-CVE-2021-37148
Dashboard / Vulnerabilities / UBUNTU-CVE-2021-37148
Summary:
Details: Improper input validation vulnerability in header parsing of Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache Traffic Server 8.0.0 to 8.1.2 and 9.0.0 to 9.0.1.
References: https://ubuntu.com/security/CVE-2021-37148, https://www.openwall.com/lists/oss-security/2021/11/02/11, https://github.com/apache/trafficserver/pull/8457/, https://github.com/apache/trafficserver/commit/6e5070118a20772a30c3fccee2cf1c44f0a21fc0, https://github.com/apache/trafficserver/commit/e2c9ac217f24dc3e91ff2c9f52b52093e8fb32d5, https://www.cve.org/CVERecord?id=CVE-2021-37148
Affected packages
Package
Name: trafficserver
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=xenial
Affected ranges
Type: ECOSYSTEM
Events:
