cbcvebase.
CVE-2021-42009
published 2021-10-12

CVE-2021-42009: An authenticated Apache Traffic Control Traffic Ops user with Portal-level privileges can send a request with a specially-crafted email subject to the…

PriorityP430medium4.3CVSS 3.1
AVNACLPRLUINSUCNILAN
EPSS
2.73%
84.5th percentile
An authenticated Apache Traffic Control Traffic Ops user with Portal-level privileges can send a request with a specially-crafted email subject to the /deliveryservices/request Traffic Ops endpoint to send an email, from the Traffic Ops server, with an arbitrary body to an arbitrary email address. Apache Traffic Control 5.1.x users should upgrade to 5.1.3 or 6.0.0. 4.1.x users should upgrade to 5.1.3.

Affected

4 ranges
VendorProductVersion rangeFixed in
apachetraffic_control>= 4.1.0 < 5.1.35.1.3
apache_software_foundationapache_traffic_control>= 4.0.0 < Apache Traffic Control*Apache Traffic Control*
github.comapache_trafficcontrol>= 0 < 5.1.3+incompatible5.1.3+incompatible
github.comapache_trafficcontrol>= 0 < 5.1.35.1.3

CVSS provenance

nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:P/A:N
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.