CVE-2021-38161: Not validating origin TLS certificate
Published Nov 3, 2021
·Updated
Improper Authentication vulnerability in TLS origin verification of Apache Traffic Server allows for man in the middle attacks. This issue affects Apache Traffic Server 8.0.0 to 8.0.8.
Affected Software
4 affected componentsFixes available
debian/trafficserver
8.0.2+ds-1+deb10u68.1.7-0+deb10u28.1.7+ds-1~deb11u19.2.0+ds-2+deb12u19.2.2+ds-1
Apache Traffic Server>=8.0.0<=8.0.8
Debian Debian Linux=10.0
Debian Debian Linux=11.0
Remediation
Event History
Nov 3, 2021
CVE Published
via MITRE·03:20 PM
Data Sourced
via MITRE·03:20 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-38161.
2
What is the severity of CVE-2021-38161?
The severity of CVE-2021-38161 is high with a severity value of 8.1.
3
What is the affected software for CVE-2021-38161?
The affected software for CVE-2021-38161 is Apache Traffic Server versions 8.0.0 to 8.0.8.
4
How does CVE-2021-38161 affect Debian Debian Linux 10.0?
CVE-2021-38161 affects Debian Debian Linux 10.0.
5
How can I fix CVE-2021-38161?
To fix CVE-2021-38161, update Apache Traffic Server to version 8.0.2+ds-1+deb10u6 or higher.