CVE-2018-11783: Infoleak
sslheaders plugin extracts information from the client certificate and sets headers in the request based on the configuration of the plugin. The plugin doesn't strip the headers from the request in some scenarios. This problem was discovered in versions 6.0.0 to 6.0.3, 7.0.0 to 7.1.5, and 8.0.0 to 8.0.1.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-11783?
CVE-2018-11783 is a vulnerability in the sslheaders plugin of Apache Traffic Server.
What does the sslheaders plugin do?
The sslheaders plugin extracts information from the client certificate and sets headers in the request based on its configuration.
Which versions of Apache Traffic Server are affected by CVE-2018-11783?
Versions 6.0.0 to 6.0.3, 7.0.0 to 7.1.5, and 8.0.0 to 8.0.1 of Apache Traffic Server are affected.
What is the severity of CVE-2018-11783?
CVE-2018-11783 has a severity rating of 7.5 (high).
How can I fix CVE-2018-11783?
To fix CVE-2018-11783, update your Apache Traffic Server to a version that is not affected.