github.com/apache/trafficcontrol
Go7 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting github.com/apache/trafficcontrolpage 1 of 1
- CVE-2017-7670HIGHCVSS 7.5EG 7.5✓ Fixed in 1.1.4-0.20170531185407-738c10fa1b582017-07-10
The Traffic Router component of the incubating Apache Traffic Control project is vulnerable to a Slowloris style Denial of Service attack. TCP connections made on the configured DNS port will remain in the ESTABLISHED state until the clien…
- CVE-2019-12405CRITICALCVSS 9.8EG 9.8✓ Fixed in 3.0.2-RC12019-09-09
Improper authentication is possible in Apache Traffic Control versions 3.0.0 and 3.0.1 if LDAP is enabled for login in the Traffic Ops API component. Given a username for a user that can be authenticated via LDAP, it is possible to imprope…
- CVE-2020-17522MEDIUMCVSS 5.8EG 5.8✓ Fixed in 5.0.02021-01-26
When ORT (now via atstccfg) generates ip_allow.config files in Apache Traffic Control 3.0.0 to 3.1.0 and 4.0.0 to 4.1.0, those files include permissions that allow bad actors to push arbitrary content into and remove arbitrary content from…
- CVE-2021-42009MEDIUMCVSS 4.3EG 4.3✓ Fixed in 5.1.3+incompatible2021-10-12
An authenticated Apache Traffic Control Traffic Ops user with Portal-level privileges can send a request with a specially-crafted email subject to the /deliveryservices/request Traffic Ops endpoint to send an email, from the Traffic Ops se…
- CVE-2021-43350CRITICALCVSS 9.8EG 9.8✓ Fixed in 6.0.1+incompatible2021-11-11
An unauthenticated Apache Traffic Control Traffic Ops user can send a request with a specially-crafted username to the POST /login endpoint of any API version to inject unsanitized content into the LDAP filter.
- CVE-2022-23206HIGHCVSS 7.5EG 7.5✓ Fixed in 6.1.0+incompatible2022-02-06
In Apache Traffic Control Traffic Ops prior to 6.1.0 or 5.1.6, an unprivileged user who can reach Traffic Ops over HTTPS can send a specially-crafted POST request to /user/login/oauth to scan a port of a server that Traffic Ops can reach.
- CVE-2024-45387CRITICALCVSS 9.9EG 9.92024-12-23
An SQL injection vulnerability in Traffic Ops in Apache Traffic Control <= 8.0.1, >= 8.0.0 allows a privileged user with role "admin", "federation", "operations", "portal", or "steering" to execute arbitrary SQL against the database by sen…
Check whether github.com/apache/trafficcontrol is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for github.com/apache/trafficcontrol CVEs against the assets you own.
Start Free Scan →