Users can use a new setting (proxy.config.acl.subjects) to choose which IP addresses to use for the ACL if Apache Traffic Server is configured to accept PROXY protocol.
This issue affects undefined: from 10.0.0 through 10.0.6, from 9.0.0 through 9.2.10.
Users are recommended to upgrade to version 9.2.11 or 10.0.6, which fixes the issue.
Subscriptions
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-5948-1 | trafficserver security update |
EUVD |
EUVD-2025-18750 | ACL configured in ip_allow.config or remap.config does not use IP addresses that are provided by PROXY protocol. Users can use a new setting (proxy.config.acl.subjects) to choose which IP addresses to use for the ACL if Apache Traffic Server is configured to accept PROXY protocol. This issue affects undefined: from 10.0.0 through 10.0.6, from 9.0.0 through 9.2.10. Users are recommended to upgrade to version 9.2.11 or 10.0.6, which fixes the issue. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 01 Jul 2025 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apache
Apache traffic Server |
|
| CPEs | cpe:2.3:a:apache:traffic_server:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Apache
Apache traffic Server |
Fri, 20 Jun 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
ssvc
|
Thu, 19 Jun 2025 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | trafficserver: Apache Traffic Server PROXY Protocol ACL Bypass | Apache Traffic Server: Client IP address from PROXY protocol is not used for ACL |
Fri, 20 Jun 2025 03:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | trafficserver: Apache Traffic Server PROXY Protocol ACL Bypass | |
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Thu, 19 Jun 2025 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ACL configured in ip_allow.config or remap.config does not use IP addresses that are provided by PROXY protocol. Users can use a new setting (proxy.config.acl.subjects) to choose which IP addresses to use for the ACL if Apache Traffic Server is configured to accept PROXY protocol. This issue affects undefined: from 10.0.0 through 10.0.6, from 9.0.0 through 9.2.10. Users are recommended to upgrade to version 9.2.11 or 10.0.6, which fixes the issue. | |
| Weaknesses | CWE-284 | |
| References |
|
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2025-06-20T13:32:19.681Z
Reserved: 2025-03-31T23:45:24.580Z
Link: CVE-2025-31698
Updated: 2025-06-20T13:31:47.401Z
Status : Analyzed
Published: 2025-06-19T10:15:20.980
Modified: 2025-07-01T20:14:42.687
Link: CVE-2025-31698
OpenCVE Enrichment
Updated: 2025-06-20T13:24:21Z
Debian DSA
EUVD