CVE-2023-33933: Apache Traffic Server: s3_auth plugin problem with hash calculation
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache Traffic Server.This issue affects Apache Traffic Server: from 8.0.0 through 9.2.0.
8.x users should upgrade to 8.1.7 or later versions 9.x users should upgrade to 9.2.1 or later versions
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/trafficserverto a version that resolves this vulnerability.Fixed in 8.1.7-0+deb10u2Fixed in 8.1.7+ds-1~deb11u1Fixed in 9.2.0+ds-2+deb12u1Fixed in 9.2.2+ds-1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 8.1.7 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 9.2.1
Event History
Frequently Asked Questions
What is CVE-2023-33933?
CVE-2023-33933 refers to the Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Traffic Server.
Which versions of Apache Traffic Server are affected by CVE-2023-33933?
CVE-2023-33933 affects Apache Traffic Server versions 8.0.0 through 9.2.0.
How can I fix CVE-2023-33933 if I am using Apache Traffic Server 8.x?
Users of Apache Traffic Server 8.x should upgrade to version 8.1.7 or a later version.
How can I fix CVE-2023-33933 if I am using Apache Traffic Server 9.x?
Users of Apache Traffic Server 9.x should upgrade to version 9.2.1 or a later version.
What is the severity of CVE-2023-33933?
CVE-2023-33933 has a severity rating of 7.5 (high).