CVE-2014-3624: Critical severity apache traffic server vulnerability
Published Oct 30, 2017
·Updated
Apache Traffic Server 5.1.x before 5.1.1 allows remote attackers to bypass access restrictions by leveraging failure to properly tunnel remap requests using CONNECT.
Affected Software
1 affected component
Apache Traffic Server=5.1.0
Remediation
Patch Available
Event History
Oct 30, 2017
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-3624?
The severity of CVE-2014-3624 is critical with a severity value of 9.8.
2
How can remote attackers exploit CVE-2014-3624?
Remote attackers can exploit CVE-2014-3624 by bypassing access restrictions through failure to properly tunnel remap requests using CONNECT.
3
Which version of Apache Traffic Server is affected by CVE-2014-3624?
Apache Traffic Server version 5.1.0 is affected by CVE-2014-3624.
4
How can I fix CVE-2014-3624?
To fix CVE-2014-3624, update your Apache Traffic Server installation to version 5.1.1 or later.
5
Where can I find more information about CVE-2014-3624?
You can find more information about CVE-2014-3624 at the following references: [1] [2] [3]