cbcvebase.
CVE-2020-17522
published 2021-01-26

CVE-2020-17522: When ORT (now via atstccfg) generates ip_allow.config files in Apache Traffic Control 3.0.0 to 3.1.0 and 4.0.0 to 4.1.0, those files include permissions that…

PriorityP335medium5.8CVSS 3.1
AVNACLPRNUINSCCNILAN
EPSS
3.93%
89.2th percentile
When ORT (now via atstccfg) generates ip_allow.config files in Apache Traffic Control 3.0.0 to 3.1.0 and 4.0.0 to 4.1.0, those files include permissions that allow bad actors to push arbitrary content into and remove arbitrary content from CDN cache servers. Additionally, these permissions are potentially extended to IP addresses outside the desired range, resulting in them being granted to clients possibly outside the CDN arcitechture.

Affected

3 ranges
VendorProductVersion rangeFixed in
apachetraffic_control3.0.0 – 3.1.0
apachetraffic_control4.0.0 – 4.1.0
github.comapache_trafficcontrol>= 0 < 5.0.05.0.0

CVSS provenance

nvdv3.15.8MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.