CyberRota Analysis
AI-GeneratedThe Apache Traffic Server ESI plugin is vulnerable to an unbounded recursion flaw that allows attackers to fetch arbitrary URLs, potentially leading to denial-of-service conditions. This high-severity vulnerability impacts versions 8.0.0 through 8.1.9, 9.0.0 through 9.2.14, and 10.0.0 through 10.1.3. Organizations using affected versions should prioritize upgrading to 9.2.15 or 10.1.4 to mitigate the risk.
Original NVD Description
The Apache Traffic Server ESI plugin can recurse without bound and fetch attacker-controlled URLs. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
Related CVEs
Other vulnerabilities affecting the same vendor(s)