CVE-2022-47184

Severity
7.5HIGH
EPSS
0.2%
top 53.53%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 14

Description

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache Traffic Server.This issue affects Apache Traffic Server: 8.0.0 to 9.2.0.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages3 packages

NVDapache/traffic_server8.0.08.1.7+1
Debiantrafficserver< 8.1.7+ds-1~deb11u1+1

Also affects: Debian Linux 11.0, 12.0

🔴Vulnerability Details

3
CVEList
Apache Traffic Server: The TRACE method can be use to disclose network information2023-06-14
GHSA
GHSA-5r5w-ww4m-44x3: Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache Traffic Server2023-06-14
OSV
CVE-2022-47184: Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache Traffic Server2023-06-14

📋Vendor Advisories

1
Debian
CVE-2022-47184: trafficserver - Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apac...2022
CVE-2022-47184 (HIGH CVSS 7.5) | Exposure of Sensitive Information t | cvebase.io