7.5
CVSSv3

CVE-2020-17509

Published: 11/01/2021 Updated: 15/01/2021
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

ATS negative cache option is vulnerable to a cache poisoning attack. If you have this option enabled, please upgrade or disable this feature. Apache Traffic Server versions 7.0.0 to 7.1.11 and 8.0.0 to 8.1.0 are affected.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apache traffic server

Vendor Advisories

Two vulnerabilities were discovered in Apache Traffic Server, a reverse and forward proxy server: CVE-2020-17508 The ESI plugin was vulnerable to memory disclosure CVE-2020-17509 The negative cache option was vulnerable to cache poisoning For the stable distribution (buster), these problems have been fixed in version 802+ds-1+deb10u4 ...