CVE-2024-53868: Apache Traffic Server: Malformed chunked message body allows request smuggling
Apache Traffic Server allows request smuggling if chunked messages are malformed.
This issue affects Apache Traffic Server: from 9.2.0 through 9.2.9, from 10.0.0 through 10.0.4.
Users are recommended to upgrade to version 9.2.10 or 10.0.5, which fixes the issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-53868?
CVE-2024-53868 has been classified as a medium severity vulnerability affecting Apache Traffic Server.
How do I fix CVE-2024-53868?
To fix CVE-2024-53868, upgrade Apache Traffic Server to version 9.2.10 or 10.0.5.
Which versions of Apache Traffic Server are affected by CVE-2024-53868?
CVE-2024-53868 affects Apache Traffic Server versions from 9.2.0 through 9.2.9 and from 10.0.0 through 10.0.4.
What type of vulnerability is CVE-2024-53868?
CVE-2024-53868 is a request smuggling vulnerability that arises from malformed chunked messages.
Is there a workaround for CVE-2024-53868?
There is no official workaround for CVE-2024-53868; upgrading to the patched versions is the recommended action.