Impact
The intercept plugin of Apache Traffic Server contains a use-after-free flaw, identified as CWE-416, which can cause memory corruption.
Affected Systems
Apache Traffic Server released by the Apache Software Foundation is vulnerable in versions 8.0.0 through 8.1.9, 9.0.0 through 9.2.14, and 10.0.0 through 10.1.3.
Risk and Exploitability
The CVSS score is 8.2 and the EPSS score is less than 1 %. The vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment