There is a vulnerability in Apache Traffic Server (ATS) 6.2.0 and prior and 7.0.0 and prior with the Host header and line folding. This can have issues when interacting with upstream proxies and the wrong host being used.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-4128-1 | trafficserver security update |
EUVD |
EUVD-2017-14740 | There is a vulnerability in Apache Traffic Server (ATS) 6.2.0 and prior and 7.0.0 and prior with the Host header and line folding. This can have issues when interacting with upstream proxies and the wrong host being used. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2024-09-17T00:37:13.932Z
Reserved: 2017-01-29T00:00:00
Link: CVE-2017-5660
No data.
Status : Modified
Published: 2018-02-27T20:29:00.403
Modified: 2024-11-21T03:28:07.817
Link: CVE-2017-5660
No data.
OpenCVE Enrichment
No data.
Weaknesses
Debian DSA
EUVD