CVE-2021-44759: Improper authentication vulnerability in TLS origin verification
Published Mar 23, 2022
·Updated
Improper Authentication vulnerability in TLS origin validation of Apache Traffic Server allows an attacker to create a man in the middle attack. This issue affects Apache Traffic Server 8.0.0 to 8.1.0.
Affected Software
4 affected componentsFixes available
debian/trafficserver
8.0.2+ds-1+deb10u68.1.7-0+deb10u28.1.7+ds-1~deb11u19.2.0+ds-2+deb12u19.2.2+ds-1
Apache Traffic Server>=8.0.0<=8.1.0
Debian Debian Linux=10.0
Debian Debian Linux=11.0
Event History
Mar 23, 2022
CVE Published
via MITRE·02:05 PM
Data Sourced
via MITRE·02:05 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-44759?
CVE-2021-44759 has a moderate severity rating due to its potential to facilitate man-in-the-middle attacks.
2
How do I fix CVE-2021-44759?
To fix CVE-2021-44759, it is recommended to update Apache Traffic Server to version 8.0.2 or later, 8.1.7 or later, or any 9.x version.
3
What versions of Apache Traffic Server are affected by CVE-2021-44759?
Apache Traffic Server versions from 8.0.0 to 8.1.0 are affected by CVE-2021-44759.
4
Can CVE-2021-44759 be exploited remotely?
Yes, CVE-2021-44759 can be exploited remotely if an attacker is able to perform man-in-the-middle attacks.
5
Is there a workaround for CVE-2021-44759 if I cannot update?
Currently, there are no known workarounds for CVE-2021-44759, so updating to a fixed version is essential.