First published: Sun Feb 06 2022(Updated: )
In Apache Traffic Control Traffic Ops prior to 6.1.0 or 5.1.6, an unprivileged user who can reach Traffic Ops over HTTPS can send a specially-crafted POST request to /user/login/oauth to scan a port of a server that Traffic Ops can reach.
Credit: security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Traffic Control | <5.1.6 | |
Apache Traffic Control | >=6.0.0<6.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.