cbcvebase.
CVE-2020-9494
published 2020-06-24

CVE-2020-9494: Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.10, and 8.0.0 to 8.0.7 is vulnerable to certain types of HTTP/2 HEADERS frames that can cause the server to…

high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.10, and 8.0.0 to 8.0.7 is vulnerable to certain types of HTTP/2 HEADERS frames that can cause the server to allocate a large amount of memory and spin the thread.

Affected

32 ranges· showing 25
VendorProductVersion rangeFixed in
apachetomcat
apachetomcat
apachetomcat7.0.0 – 7.0.107
apachetomcat8.5.0 – 8.5.61
apachetomcat9.0.0 – 9.0.41
apachetraffic_server6.0.0 – 6.2.3
apachetraffic_server7.0.0 – 7.1.10
apachetraffic_server8.0.0 – 8.0.7
apache_software_foundationapache_traffic_server
apache_software_foundationapache_traffic_server
apache_software_foundationapache_traffic_server
debiandebian_linux
debiandebian_linux
debiantomcat9< tomcat9 9.0.43-1 (bookworm)tomcat9 9.0.43-1 (bookworm)
debiantrafficserver< trafficserver 8.0.8+ds-1 (bookworm)trafficserver 8.0.8+ds-1 (bookworm)
oracleagile_plm
oracleagile_plm
oraclecommunications_cloud_native_core_policy
oraclecommunications_cloud_native_core_security_edge_protection_proxy
oraclecommunications_instant_messaging_server
oracledatabase
oracledatabase
oracledatabase
oraclegraph_server_and_client< 21.3.021.3.0
oracleinstantis_enterprisetrack

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
ghsa7.0HIGH
osv7.5HIGH