CVE-2019-17565
published 2020-03-23CVE-2019-17565: There is a vulnerability in Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.8, and 8.0.0 to 8.0.5 with a smuggling attack and chunked encoding. Upgrade to…
PriorityP353critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
3.09%
86.2th percentile
There is a vulnerability in Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.8, and 8.0.0 to 8.0.5 with a smuggling attack and chunked encoding. Upgrade to versions 7.1.9 and 8.0.6 or later versions.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | traffic_server | 6.0.0 – 6.2.3 | — |
| apache | traffic_server | 7.0.0 – 7.1.8 | — |
| apache | traffic_server | 8.0.0 – 8.0.5 | — |
| debian | debian_linux | — | — |
| debian | trafficserver | < trafficserver 8.0.6+ds-1 (bookworm) | trafficserver 8.0.6+ds-1 (bookworm) |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2v7c-2x99-gv22: There is a vulnerability in Apache Traffic Server 6
ghsa_unreviewed·2022-05-24
CVE-2019-17565 [HIGH] CWE-444 GHSA-2v7c-2x99-gv22: There is a vulnerability in Apache Traffic Server 6
There is a vulnerability in Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.8, and 8.0.0 to 8.0.5 with a smuggling attack and chunked encoding. Upgrade to versions 7.1.9 and 8.0.6 or later versions.
OSV
CVE-2019-17565: There is a vulnerability in Apache Traffic Server 6
osv·2020-03-23·CVSS 9.8
CVE-2019-17565 [CRITICAL] CVE-2019-17565: There is a vulnerability in Apache Traffic Server 6
There is a vulnerability in Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.8, and 8.0.0 to 8.0.5 with a smuggling attack and chunked encoding. Upgrade to versions 7.1.9 and 8.0.6 or later versions.
Debian
CVE-2019-17565: trafficserver - There is a vulnerability in Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.8...
vendor_debian·2019·CVSS 9.8
CVE-2019-17565 [CRITICAL] CVE-2019-17565: trafficserver - There is a vulnerability in Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.8...
There is a vulnerability in Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.8, and 8.0.0 to 8.0.5 with a smuggling attack and chunked encoding. Upgrade to versions 7.1.9 and 8.0.6 or later versions.
Scope: local
bookworm: resolved (fixed in 8.0.6+ds-1)
bullseye: resolved (fixed in 8.0.6+ds-1)
sid: resolved (fixed in 8.0.6+ds-1)
No detection rules found.
No public exploits indexed.
https://lists.apache.org/thread.html/r99d18d0bc4daa05e7d0e5a63e0e22701a421b2ef5a8f4f7694c43869%40%3Cannounce.trafficserver.apache.org%3Ehttps://www.debian.org/security/2020/dsa-4672https://lists.apache.org/thread.html/r99d18d0bc4daa05e7d0e5a63e0e22701a421b2ef5a8f4f7694c43869%40%3Cannounce.trafficserver.apache.org%3Ehttps://www.debian.org/security/2020/dsa-4672
2020-03-23
Published