CVE-2022-31778: Transfer-Encoding not treated as hop-by-hop
Published Aug 10, 2022
·Updated
Improper Input Validation vulnerability in handling the Transfer-Encoding header of Apache Traffic Server allows an attacker to poison the cache. This issue affects Apache Traffic Server 8.0.0 to 9.0.2.
Affected Software
4 affected componentsFixes available
debian/trafficserver<=8.0.2+ds-1+deb10u6
8.1.7-0+deb10u28.1.7+ds-1~deb11u19.2.0+ds-2+deb12u19.2.2+ds-1
Apache Traffic Server>=8.0.0<=8.1.4
Apache Traffic Server>=9.0.0<=9.1.2
Debian Debian Linux=11.0
Event History
Aug 10, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID is CVE-2022-31778.
2
What is the severity of CVE-2022-31778?
The severity of CVE-2022-31778 is high with a score of 7.5.
3
How does CVE-2022-31778 affect Apache Traffic Server?
CVE-2022-31778 affects Apache Traffic Server versions 8.0.0 to 9.0.2.
4
How can an attacker exploit CVE-2022-31778?
An attacker can exploit CVE-2022-31778 by poisoning the cache through improper input validation in handling the Transfer-Encoding header of Apache Traffic Server.
5
How can I fix CVE-2022-31778?
To fix CVE-2022-31778, update Apache Traffic Server to versions 8.1.7 or 9.2.2 or higher.