CVE-2020-17509: High severity apache traffic server vulnerability
ATS negative cache option is vulnerable to a cache poisoning attack. If you have this option enabled, please upgrade or disable this feature. Apache Traffic Server versions 7.0.0 to 7.1.11 and 8.0.0 to 8.1.0 are affected.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this security issue?
The vulnerability ID of this security issue is CVE-2020-17509.
What is the severity level of CVE-2020-17509?
CVE-2020-17509 has a severity level of high.
How is Apache Traffic Server affected by this vulnerability?
Apache Traffic Server versions 7.0.0 to 7.1.11 and 8.0.0 to 8.1.0 are affected by this vulnerability.
What is the recommended action to mitigate this vulnerability?
It is recommended to upgrade Apache Traffic Server to a version that is not affected by this vulnerability or disable the ATS negative cache option.
Where can I find more information about CVE-2020-17509?
You can find more information about CVE-2020-17509 at the following URL: https://lists.apache.org/thread.html/raa9f0589c26c4d146646425e51e2a33e1457492df9f7ea2019daa6d3%40%3Cannounce.trafficserver.apache.org%3E