CVE-2021-27577: Incorrect handling of url fragment leads to cache poisoning
Published Jun 29, 2021
·Updated
Incorrect handling of url fragment vulnerability of Apache Traffic Server allows an attacker to poison the cache. This issue affects Apache Traffic Server 7.0.0 to 7.1.12, 8.0.0 to 8.1.1, 9.0.0 to 9.0.1.
Affected Software
5 affected componentsFixes available
debian/trafficserver
8.0.2+ds-1+deb10u68.1.7-0+deb10u28.1.7+ds-1~deb11u19.2.0+ds-2+deb12u19.2.2+ds-1
Apache Traffic Server>=7.0.0<=7.1.12
Apache Traffic Server>=8.0.0<=8.1.1
Apache Traffic Server>=9.0.0<=9.0.1
Debian Debian Linux=8.0
Event History
Jun 29, 2021
CVE Published
via MITRE·11:45 AM
Data Sourced
via MITRE·11:45 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-27577.
2
What is the severity level of CVE-2021-27577?
The severity level of CVE-2021-27577 is high.
3
How does the vulnerability affect Apache Traffic Server?
The vulnerability affects Apache Traffic Server version 7.0.0 to 7.1.12, 8.0.0 to 8.1.1, and 9.0.0 to 9.0.1.
4
How can an attacker exploit this vulnerability?
An attacker can exploit this vulnerability to poison the cache of Apache Traffic Server.
5
What are the recommended versions to fix this vulnerability?
The recommended versions to fix this vulnerability are 8.0.2+ds-1+deb10u6, 8.1.7-0+deb10u2, 8.1.7+ds-1~deb11u1, 9.2.0+ds-2+deb12u1, and 9.2.2+ds-1.