Impact
The prefetch plugin in Apache Traffic Server is vulnerable to a crash when it processes input that an attacker can influence. This flaw is an input validation error, which can cause the server to terminate unexpectedly, leading to a denial of service for legitimate users.
Affected Systems
Apache Traffic Server from version 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, and from 10.0.0 through 10.1.3.
Risk and Exploitability
The CVSS score of 8.2 indicates a high severity, but the EPSS score is below 1%, suggesting a low probability of exploitation at present. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, it is inferred that the crash can be triggered over the network by sending crafted requests to the prefetch plugin. Accordingly, the likely attack vector is remote, originating from an external client or an internal adversary with network access.
OpenCVE Enrichment