CVE-2020-9481Uncontrolled Resource Consumption in Apache Traffic Server

Severity
7.5HIGHNVD
EPSS
5.2%
top 10.03%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 27
Latest updateMay 24

Description

Apache ATS 6.0.0 to 6.2.3, 7.0.0 to 7.1.9, and 8.0.0 to 8.0.6 is vulnerable to a HTTP/2 slow read attack.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages2 packages

NVDapache/traffic_server6.0.06.2.3+2
CVEListV5apache/ats6.0.0 to 6.2.3, 7.0.0 to 7.1.9, 8.0.0 to 8.0.6+2

Also affects: Debian Linux 10.0

Patches

🔴Vulnerability Details

3
GHSA
GHSA-p73f-98x4-6v7q: Apache ATS 62022-05-24
CVEList
CVE-2020-9481: Apache ATS 62020-04-27
OSV
CVE-2020-9481: Apache ATS 62020-04-27

📋Vendor Advisories

1
Debian
CVE-2020-9481: trafficserver - Apache ATS 6.0.0 to 6.2.3, 7.0.0 to 7.1.9, and 8.0.0 to 8.0.6 is vulnerable to a...2020
CVE-2020-9481 — Uncontrolled Resource Consumption | cvebase