UBUNTU-CVE-2021-37149
Dashboard / Vulnerabilities / UBUNTU-CVE-2021-37149
Summary:
Details: Improper Input Validation vulnerability in header parsing of Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache Traffic Server 8.0.0 to 8.1.2 and 9.0.0 to 9.1.0.
References: https://ubuntu.com/security/CVE-2021-37149, https://www.openwall.com/lists/oss-security/2021/11/02/11, https://github.com/apache/trafficserver/pull/8458/, https://github.com/apache/trafficserver/commit/2addc8ca71449ceac0d5b80172460ee09c938f5e, https://github.com/apache/trafficserver/commit/83c89f3d217d473ecb000b68c910c0f183c3a355, https://www.cve.org/CVERecord?id=CVE-2021-37149
Affected packages
Package
Name: trafficserver
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=xenial
Affected ranges
Type: ECOSYSTEM
Events:
