Exposição de Apache Traffic Server

Web servers
123
score de exposição
3.251
sites usam
0
em exploração
7
críticos
Análise Vexday

Com 63 CVEs catalogadas e nenhuma confirmada em exploração ativa pelo catálogo CISA KEV, o Apache Traffic Server apresenta taxa de exploração abaixo da média geral, o que pode refletir sua presença em ambientes mais especializados. No entanto, o alto escore EPSS de 0,94615 registrado na CVE-2024-31309 — associada a falhas de validação de entrada (CWE-20, o tipo de falha mais frequente nessa tecnologia) — indica probabilidade elevada de exploração, exigindo atenção prioritária independentemente da ausência de confirmações KEV. Das 63 vulnerabilidades, 3 são classificadas como críticas, e 2 surgiram nos últimos 90 dias, sinalizando uma superfície de ataque ainda ativa. Equipes que operam o Apache Traffic Server devem tratar CVE-2024-31309 como prioridade imediata de remediação, dado o risco quantificado pelo modelo preditivo EPSS.

CVEs

102 resultados
CVE-2021-44759—Improper authentication vulnerability in TLS origin verificationEPSS 1.6%CVE-2024-50306CRITICALApache Traffic Server: Server process can fail to drop privilegeEPSS 1.6%CVE-2023-33934CRITICALApache Traffic Server: Differential fuzzing for HTTP request parsing discrepanciesEPSS 1.6%CVE-2022-47184HIGHApache Traffic Server: The TRACE method can be use to disclose network informationEPSS 1.5%CVE-2023-33933HIGHApache Traffic Server: s3_auth plugin problem with hash calculationEPSS 1.5%CVE-2022-32749HIGHApache Traffic Server: Improperly handled requests can cause crashes in specific pluginsEPSS 1.3%CVE-2023-41752HIGHApache Traffic Server: s3_auth plugin problem with hash calculationEPSS 1.2%CVE-2022-37392MEDIUMApache Traffic Server: Improperly reading the client requestsEPSS 1.1%CVE-2022-40743MEDIUMApache Traffic Server: Security issues with the xdebug pluginEPSS 1.1%CVE-2024-35296HIGHApache Traffic Server: Invalid Accept-Encoding can force forwarding requestsEPSS 1.1%CVE-2023-38522HIGHApache Traffic Server: Incomplete field name check allows request smugglingEPSS 1.0%CVE-2024-35161CRITICALApache Traffic Server: Incomplete check for chunked trailer section allows request smugglingEPSS 1.0%CVE-2024-50305HIGHApache Traffic Server: Valid Host field value can cause crashesEPSS 0.9%CVE-2024-38311MEDIUMApache Traffic Server: Request smuggling via pipelining after a chunked message bodyEPSS 0.9%CVE-2024-56202MEDIUMApache Traffic Server: Expect header field can unreasonably retain resourceEPSS 0.9%CVE-2024-38479HIGHApache Traffic Server: Cache key plugin is vulnerable to cache poisoning attackEPSS 0.8%CVE-2024-56195MEDIUMApache Traffic Server: Intercept plugins are not access controlledEPSS 0.8%CVE-2024-56196MEDIUMApache Traffic Server: ACL is not fully compatible with older versionsEPSS 0.8%CVE-2026-58188HIGHApache Traffic Server: Memory-safety and limit-bypass errors across experimental pluginsEPSS 0.8%CVE-2025-49763HIGHApache Traffic Server: Remote DoS via memory exhaustion in ESI PluginEPSS 0.7%