First published: Tue Feb 12 2019(Updated: )
sslheaders plugin extracts information from the client certificate and sets headers in the request based on the configuration of the plugin. The plugin doesn't strip the headers from the request in some scenarios. This problem was discovered in versions 6.0.0 to 6.0.3, 7.0.0 to 7.1.5, and 8.0.0 to 8.0.1.
Credit: security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Traffic Server | >=6.0.0<=6.0.3 | |
Apache Traffic Server | >=7.0.0<=7.1.5 | |
Apache Traffic Server | >=8.0.0<=8.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-11783 is a vulnerability in the sslheaders plugin of Apache Traffic Server.
The sslheaders plugin extracts information from the client certificate and sets headers in the request based on its configuration.
Versions 6.0.0 to 6.0.3, 7.0.0 to 7.1.5, and 8.0.0 to 8.0.1 of Apache Traffic Server are affected.
CVE-2018-11783 has a severity rating of 7.5 (high).
To fix CVE-2018-11783, update your Apache Traffic Server to a version that is not affected.