CVE-2021-37148: Request Smuggling - transfer encoding validation
Improper input validation vulnerability in header parsing of Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache Traffic Server 8.0.0 to 8.1.2 and 9.0.0 to 9.0.1.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2021-37148?
CVE-2021-37148 is an improper input validation vulnerability in the header parsing of Apache Traffic Server.
How does CVE-2021-37148 affect Apache Traffic Server?
CVE-2021-37148 allows an attacker to smuggle requests in Apache Traffic Server versions 8.0.0 to 8.1.2 and 9.0.0 to 9.0.1.
Which software versions are affected by CVE-2021-37148?
Apache Traffic Server versions 8.0.0 to 8.1.2 and 9.0.0 to 9.0.1 are affected by CVE-2021-37148.
What is the severity of CVE-2021-37148?
CVE-2021-37148 has a severity value of 7.5, which is considered high.
How can I fix CVE-2021-37148?
To fix CVE-2021-37148, update Apache Traffic Server to versions 8.0.2+ds-1+deb10u6, 8.1.7-0+deb10u2, 8.1.7+ds-1~deb11u1, 9.2.0+ds-2+deb12u1, or 9.2.2+ds-1, depending on your distribution.