CVE-2022-40743Cross-site Scripting in Software Foundation Apache Traffic Server

Severity
6.1MEDIUMNVD
EPSS
8.2%
top 7.77%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 19

Description

Improper Input Validation vulnerability for the xdebug plugin in Apache Software Foundation Apache Traffic Server can lead to cross site scripting and cache poisoning attacks.This issue affects Apache Traffic Server: 9.0.0 to 9.1.3. Users should upgrade to 9.1.4 or later versions.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages2 packages

NVDapache/traffic_server8.0.08.1.5+1

🔴Vulnerability Details

3
OSV
CVE-2022-40743: Improper Input Validation vulnerability for the xdebug plugin in Apache Software Foundation Apache Traffic Server can lead to cross site scripting and2022-12-19
CVEList
Apache Traffic Server: Security issues with the xdebug plugin2022-12-19
GHSA
GHSA-q99x-rwh5-433q: Improper Input Validation vulnerability for the xdebug plugin in Apache Software Foundation Apache Traffic Server can lead to cross site scripting and2022-12-19

📋Vendor Advisories

1
Debian
CVE-2022-40743: trafficserver - Improper Input Validation vulnerability for the xdebug plugin in Apache Software...2022
CVE-2022-40743 — Cross-site Scripting | cvebase