CVE-2024-56195: Apache Traffic Server: Intercept plugins are not access controlled
Improper Access Control vulnerability in Apache Traffic Server.
This issue affects Apache Traffic Server: from 9.2.0 through 9.2.8, from 10.0.0 through 10.0.3.
Users are recommended to upgrade to version 9.2.9 or 10.0.4, which fixes the issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-56195?
CVE-2024-56195 has been classified as a medium severity vulnerability due to improper access control in Apache Traffic Server.
How do I fix CVE-2024-56195?
To fix CVE-2024-56195, upgrade Apache Traffic Server to version 9.2.9 or 10.0.4.
Which versions of Apache Traffic Server are affected by CVE-2024-56195?
CVE-2024-56195 affects Apache Traffic Server versions from 9.2.0 to 9.2.8 and 10.0.0 to 10.0.3.
What is the nature of the vulnerability in CVE-2024-56195?
CVE-2024-56195 involves improper access control which could potentially allow unauthorized users to access restricted resources.
Is there a recommended upgrade path for CVE-2024-56195?
Yes, users should upgrade to Apache Traffic Server version 9.2.9 or 10.0.4 to mitigate the risks associated with CVE-2024-56195.