CyberRota Analysis
AI-GeneratedApache Traffic Server versions 8.0.0 to 8.1.9, 9.0.0 to 9.2.14, and 10.0.0 to 10.1.3 are vulnerable due to improper parsing of ports in URLs and userinfo, which can lead to unauthorized access through port-based access control bypass. Organizations using these affected versions should prioritize upgrading to versions 9.2.15 or 10.1.4 to mitigate potential security risks. This vulnerability is particularly relevant for environments relying on Apache Traffic Server for traffic management and access control.
Original NVD Description
Apache Traffic Server mis-parses ports in URLs and userinfo, allowing port-based access-control bypass. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
Related CVEs
Other vulnerabilities affecting the same vendor(s)