CVE-2024-56196: Apache Traffic Server: ACL is not fully compatible with older versions
Published Mar 6, 2025
·Updated
Improper Access Control vulnerability in Apache Traffic Server.
This issue affects Apache Traffic Server: from 10.0.0 through 10.0.3.
Users are recommended to upgrade to version 10.0.4, which fixes the issue.
Affected Software
2 affected components
Apache Traffic Server>=10.0.0<=10.0.3
Apache Traffic Server>=10.0.0<10.0.4
Event History
Mar 6, 2025
CVE Published
via MITRE·11:21 AM
Data Sourced
via MITRE·11:21 AM
DescriptionWeakness
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-56196?
CVE-2024-56196 is rated as a medium severity vulnerability.
2
How do I fix CVE-2024-56196?
To fix CVE-2024-56196, upgrade Apache Traffic Server to version 10.0.4 or later.
3
What versions of Apache Traffic Server are affected by CVE-2024-56196?
CVE-2024-56196 affects Apache Traffic Server versions from 10.0.0 to 10.0.3.
4
What type of vulnerability is CVE-2024-56196?
CVE-2024-56196 is classified as an improper access control vulnerability.
5
Is there a workaround for CVE-2024-56196?
There are no known workarounds for CVE-2024-56196; updating to the fixed version is recommended.