5
CVSSv2

CVE-2017-5660

Published: 27/02/2018 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 8.6 | Impact Score: 4 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

There is a vulnerability in Apache Traffic Server (ATS) 6.2.0 and prior and 7.0.0 and prior with the Host header and line folding. This can have issues when interacting with upstream proxies and the wrong host being used.

Vulnerable Product Search on Vulmon Subscribe to Product

apache traffic server

apache traffic server 7.0.0

apache traffic server 6.2.1

apache traffic server 6.2.2

debian debian linux 9.0

Vendor Advisories

Several vulnerabilities were discovered in Apache Traffic Server, a reverse and forward proxy server They could lead to the use of an incorrect upstream proxy, or allow a remote attacker to cause a denial-of-service by application crash For the stable distribution (stretch), these problems have been fixed in version 700-6+deb9u1 We recommend t ...