CVE-2020-17508: High severity apache traffic server vulnerability
Published Jan 11, 2021
·Updated
The ATS ESI plugin has a memory disclosure vulnerability. If you are running the plugin please upgrade. Apache Traffic Server versions 7.0.0 to 7.1.11 and 8.0.0 to 8.1.0 are affected.
Affected Software
3 affected components
Apache Traffic Server>=6.0.0<=6.2.3
Apache Traffic Server>=7.0.0<=7.1.11
Apache Traffic Server>=8.0.0<=8.1.0
Event History
Jan 11, 2021
CVE Published
via MITRE·09:40 AM
Data Sourced
via MITRE·09:40 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2020-17508?
The severity of CVE-2020-17508 is high.
2
Which versions of Apache Traffic Server are affected by CVE-2020-17508?
Apache Traffic Server versions 7.0.0 to 7.1.11 and 8.0.0 to 8.1.0 are affected by CVE-2020-17508.
3
What is the recommended action for CVE-2020-17508?
If you are running the ATS ESI plugin, please upgrade to a version that fixes the vulnerability.
4
Is there a reference link for more information about CVE-2020-17508?
Yes, you can find more information about CVE-2020-17508 at the following link: [Reference Link](https://lists.apache.org/thread.html/r65434f7acca3aebf81b0588587149c893fe9f8f9f159eaa7364a70ff%40%3Cannounce.trafficserver.apache.org%3E)