CVE-2024-50306
published 2024-11-14CVE-2024-50306: Unchecked return value can allow Apache Traffic Server to retain privileges on startup. This issue affects Apache Traffic Server: from 9.2.0 through 9.2.5…
PriorityP355critical9.1CVSS 3.1
AVNACLPRNUINSUCNIHAH
EPSS
1.58%
72.8th percentile
Unchecked return value can allow Apache Traffic Server to retain privileges on startup.
This issue affects Apache Traffic Server: from 9.2.0 through 9.2.5, from 10.0.0 through 10.0.1.
Users are recommended to upgrade to version 9.2.6 or 10.0.2, which fixes the issue.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | traffic_server | >= 10.0.0 < 10.0.2 | 10.0.2 |
| apache | traffic_server | >= 9.0.0 < 9.2.6 | 9.2.6 |
| apache_software_foundation | apache_traffic_server | 10.0.0 – 10.0.1 | — |
| apache_software_foundation | apache_traffic_server | 9.2.0 – 9.2.5 | — |
| debian | trafficserver | < trafficserver 9.2.5+ds-0+deb12u2 (bookworm) | trafficserver 9.2.5+ds-0+deb12u2 (bookworm) |
CVSS provenance
nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
osv9.1CRITICAL
vendor_debian9.1CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6j2p-q7p9-hmxw: Unchecked return value can allow Apache Traffic Server to retain privileges on startup
ghsa_unreviewed·2024-11-14
CVE-2024-50306 [CRITICAL] CWE-252 GHSA-6j2p-q7p9-hmxw: Unchecked return value can allow Apache Traffic Server to retain privileges on startup
Unchecked return value can allow Apache Traffic Server to retain privileges on startup.
This issue affects Apache Traffic Server: from 9.2.0 through 9.2.5, from 10.0.0 through 10.0.1.
Users are recommended to upgrade to version 9.2.6 or 10.0.2, which fixes the issue.
OSV
CVE-2024-50306: Unchecked return value can allow Apache Traffic Server to retain privileges on startup
osv·2024-11-14·CVSS 9.1
CVE-2024-50306 [CRITICAL] CVE-2024-50306: Unchecked return value can allow Apache Traffic Server to retain privileges on startup
Unchecked return value can allow Apache Traffic Server to retain privileges on startup. This issue affects Apache Traffic Server: from 9.2.0 through 9.2.5, from 10.0.0 through 10.0.1. Users are recommended to upgrade to version 9.2.6 or 10.0.2, which fixes the issue.
Debian
CVE-2024-50306: trafficserver - Unchecked return value can allow Apache Traffic Server to retain privileges on s...
vendor_debian·2024·CVSS 9.1
CVE-2024-50306 [CRITICAL] CVE-2024-50306: trafficserver - Unchecked return value can allow Apache Traffic Server to retain privileges on s...
Unchecked return value can allow Apache Traffic Server to retain privileges on startup. This issue affects Apache Traffic Server: from 9.2.0 through 9.2.5, from 10.0.0 through 10.0.1. Users are recommended to upgrade to version 9.2.6 or 10.0.2, which fixes the issue.
Scope: local
bookworm: resolved (fixed in 9.2.5+ds-0+deb12u2)
bullseye: resolved (fixed in 8.1.11+ds-0+deb11u2)
sid: open
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-11-14
Published