9.8
CVSSv3

CVE-2014-3624

Published: 30/10/2017 Updated: 07/11/2023
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Apache Traffic Server 5.1.x prior to 5.1.1 allows remote malicious users to bypass access restrictions by leveraging failure to properly tunnel remap requests using CONNECT.

Vulnerable Product Search on Vulmon Subscribe to Product

apache traffic server 5.1.0

Vendor Advisories

Debian Bug report logs - #778895 trafficserver: CVE-2014-10022 Package: trafficserver; Maintainer for trafficserver is Jean Baptiste Favre <debian@jbfavreorg>; Source for trafficserver is src:trafficserver (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@inutilorg> Date: Sat, 21 Feb 2015 13:27:01 UTC Sev ...