CVE-2021-37149: Request Smuggling - multiple attacks
Published Nov 3, 2021
·Updated
Improper Input Validation vulnerability in header parsing of Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache Traffic Server 8.0.0 to 8.1.2 and 9.0.0 to 9.1.0.
Affected Software
5 affected componentsFixes available
debian/trafficserver
8.0.2+ds-1+deb10u68.1.7-0+deb10u28.1.7+ds-1~deb11u19.2.0+ds-2+deb12u19.2.2+ds-1
Apache Traffic Server>=8.0.0<=8.1.2
Apache Traffic Server>=9.0.0<=9.1.0
Debian Debian Linux=10.0
Debian Debian Linux=11.0
Remediation
Event History
Nov 3, 2021
CVE Published
via MITRE·03:20 PM
Data Sourced
via MITRE·03:20 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2021-37149.
2
What is the severity of CVE-2021-37149?
The severity of CVE-2021-37149 is high, with a severity value of 7.5.
3
Which software versions are affected by CVE-2021-37149?
CVE-2021-37149 affects Apache Traffic Server versions 8.0.0 to 8.1.2 and 9.0.0 to 9.1.0.
4
How can an attacker exploit CVE-2021-37149?
An attacker can exploit CVE-2021-37149 by smuggling requests through improper input validation in header parsing of Apache Traffic Server.
5
Is there a fix available for CVE-2021-37149?
Yes, there are fixes available for CVE-2021-37149. Please refer to the references for more information.