CVE-2018-8040: Medium severity apache traffic server vulnerability
Pages that are rendered using the ESI plugin can have access to the cookie header when the plugin is configured not to allow access. This affects Apache Traffic Server (ATS) versions 6.0.0 to 6.2.2 and 7.0.0 to 7.1.3. To resolve this issue users running 6.x should upgrade to 6.2.3 or later versions and 7.x users should upgrade to 7.1.4 or later versions.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2018-8040.
What is the severity of CVE-2018-8040?
The severity of CVE-2018-8040 is medium.
Which software versions are affected by CVE-2018-8040?
Apache Traffic Server versions 6.0.0 to 6.2.2 and 7.0.0 to 7.1.3 are affected by CVE-2018-8040.
How can I fix CVE-2018-8040?
To resolve this issue, users running Apache Traffic Server 6.x should upgrade to version 6.2.3 or later versions.
Where can I find more information about CVE-2018-8040?
More information about CVE-2018-8040 can be found at the following references: [reference 1](https://www.openwall.com/lists/oss-security/2018/08/29/2), [reference 2](https://github.com/apache/trafficserver/pull/3926), [reference 3](https://github.com/apache/trafficserver/commit/cea07c03274807c1588dbdf03baa1537d958c92f).