CVE-2020-17509

Severity
7.5HIGH
EPSS
3.0%
top 13.31%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 11
Latest updateMay 24

Description

ATS negative cache option is vulnerable to a cache poisoning attack. If you have this option enabled, please upgrade or disable this feature. Apache Traffic Server versions 7.0.0 to 7.1.11 and 8.0.0 to 8.1.0 are affected.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages3 packages

NVDapache/traffic_server6.0.06.2.3+2
CVEListV5apache_traffic_serverApache Traffic Server 7.0.0 to 7.1.11, 8.0.0 to 8.1.0
Debiantrafficserver< 8.1.1+ds-1+1

🔴Vulnerability Details

3
GHSA
GHSA-wgc8-c98w-8fvh: ATS negative cache option is vulnerable to a cache poisoning attack2022-05-24
CVEList
CVE-2020-17509: ATS negative cache option is vulnerable to a cache poisoning attack2021-01-11
OSV
CVE-2020-17509: ATS negative cache option is vulnerable to a cache poisoning attack2021-01-11

📋Vendor Advisories

1
Debian
CVE-2020-17509: trafficserver - ATS negative cache option is vulnerable to a cache poisoning attack. If you have...2020
CVE-2020-17509 (HIGH CVSS 7.5) | ATS negative cache option is vulner | cvebase.io