CVE-2022-47184: Apache Traffic Server: The TRACE method can be use to disclose network information
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache Traffic Server.This issue affects Apache Traffic Server: 8.0.0 to 9.2.0.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-47184?
CVE-2022-47184 is a vulnerability that allows the exposure of sensitive information to an unauthorized actor in Apache Traffic Server.
Which software versions are affected by CVE-2022-47184?
CVE-2022-47184 affects Apache Traffic Server versions 8.0.0 to 9.2.0.
What is the severity of CVE-2022-47184?
CVE-2022-47184 has a severity level of 7.5 (high).
How can I fix CVE-2022-47184?
To fix CVE-2022-47184, update Apache Traffic Server to version 9.2.1 or higher.
Where can I find more information about CVE-2022-47184?
You can find more information about CVE-2022-47184 at the following references: [link1](https://lists.apache.org/thread/tns2b4khyyncgs5v5p9y35pobg9z2bvs), [link2](https://lists.debian.org/debian-lts-announce/2023/06/msg00037.html), [link3](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6GDCBNFDDW6ULW7CACJCPENI7BVDHM5O/)