Apache Traffic Server 5.1.x before 5.1.1 allows remote attackers to bypass access restrictions by leveraging failure to properly tunnel remap requests using CONNECT.
References
Link | Resource |
---|---|
http://mail-archives.apache.org/mod_mbox/www-announce/201411.mbox/%3C20141101231749.2E3561043F%40minotaur.apache.org%3E | |
http://www.securityfocus.com/bid/101630 | Third Party Advisory VDB Entry |
https://issues.apache.org/jira/browse/TS-2677 | Issue Tracking Patch Vendor Advisory |
http://mail-archives.apache.org/mod_mbox/www-announce/201411.mbox/%3C20141101231749.2E3561043F%40minotaur.apache.org%3E | |
http://www.securityfocus.com/bid/101630 | Third Party Advisory VDB Entry |
https://issues.apache.org/jira/browse/TS-2677 | Issue Tracking Patch Vendor Advisory |
Configurations
History
21 Nov 2024, 02:08
Type | Values Removed | Values Added |
---|---|---|
References | () http://mail-archives.apache.org/mod_mbox/www-announce/201411.mbox/%3C20141101231749.2E3561043F%40minotaur.apache.org%3E - | |
References | () http://www.securityfocus.com/bid/101630 - Third Party Advisory, VDB Entry | |
References | () https://issues.apache.org/jira/browse/TS-2677 - Issue Tracking, Patch, Vendor Advisory |
07 Nov 2023, 02:20
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
Information
Published : 2017-10-30 14:29
Updated : 2024-11-21 02:08
NVD link : CVE-2014-3624
Mitre link : CVE-2014-3624
CVE.ORG link : CVE-2014-3624
JSON object : View
Products Affected
apache
- traffic_server
CWE
CWE-284
Improper Access Control