CVE-2018-8040
3Vexday Risk Score
Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.
ssvc Trackepss 7.2%
probabilidade de exploração
7.2%top 6% das CVEs
exploração observada
nãonenhuma fonte reporta
Pages that are rendered using the ESI plugin can have access to the cookie header when the plugin is configured not to allow access. This affects Apache Traffic Server (ATS) versions 6.0.0 to 6.2.2 and 7.0.0 to 7.1.3. To resolve this issue users running 6.x should upgrade to 6.2.3 or later versions and 7.x users should upgrade to 7.1.4 or later versions.
Produtos afetados
Apache Software Foundation · Apache Traffic ServerReferências
https://github.com/apache/trafficserver/pull/3926https://lists.apache.org/thread.html/36b3df68fe7311965f6bc4630ca413d2aa99d8f1d53affda85ea70d7%40%3Cusers.trafficserver.apache.org%3Ehttps://lists.apache.org/thread.html/cc7aa2ce1c6f4fe0c6bfef517763cdaad30ec7bcb0115b73f73f3c01%40%3Cusers.trafficserver.apache.org%3Ehttps://www.debian.org/security/2018/dsa-4282http://www.securityfocus.com/bid/105181