CVE-2023-30631: Apache Traffic Server: Configuration option to block the PUSH method in ATS didn't work
Improper Input Validation vulnerability in Apache Software Foundation Apache Traffic Server. The configuration option proxy.config.http.pushmethodenabled didn't function. However, by default the PUSH method is blocked in the ipallow configuration file.This issue affects Apache Traffic Server: from 8.0.0 through 9.2.0.
8.x users should upgrade to 8.1.7 or later versions 9.x users should upgrade to 9.2.1 or later versions
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-30631?
CVE-2023-30631 refers to an Improper Input Validation vulnerability in Apache Traffic Server.
What is the severity of CVE-2023-30631?
CVE-2023-30631 has a severity rating of 7.5 (high).
What is affected by CVE-2023-30631?
Apache Traffic Server versions 8.0.0 to 8.1.7 and versions 9.0.0 to 9.2.1 are affected by CVE-2023-30631.
How does CVE-2023-30631 impact the configuration option proxy.config.http.push_method_enabled?
CVE-2023-30631 causes the configuration option proxy.config.http.push_method_enabled to not function properly in Apache Traffic Server.
How can I fix CVE-2023-30631?
To fix CVE-2023-30631, update Apache Traffic Server to version 8.1.7 or 9.2.2, or apply the appropriate remedy patches provided by the Debian LTS or Fedora Project.