CVE Vulnerabilities

CVE-2020-17508

Published: Jan 11, 2021 | Modified: Jul 21, 2021
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
LOW

The ATS ESI plugin has a memory disclosure vulnerability. If you are running the plugin please upgrade. Apache Traffic Server versions 7.0.0 to 7.1.11 and 8.0.0 to 8.1.0 are affected.

Affected Software

Name Vendor Start Version End Version
Traffic_server Apache 6.0.0 (including) 6.2.3 (including)
Traffic_server Apache 7.0.0 (including) 7.1.11 (including)
Traffic_server Apache 8.0.0 (including) 8.1.0 (including)
Trafficserver Ubuntu bionic *
Trafficserver Ubuntu esm-apps/bionic *
Trafficserver Ubuntu esm-apps/focal *
Trafficserver Ubuntu esm-apps/xenial *
Trafficserver Ubuntu focal *
Trafficserver Ubuntu groovy *
Trafficserver Ubuntu trusty *
Trafficserver Ubuntu upstream *
Trafficserver Ubuntu xenial *

References