CVE-2021-38161

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
03/11/2021
Last modified:
25/10/2022

Description

Improper Authentication vulnerability in TLS origin verification of Apache Traffic Server allows for man in the middle attacks. This issue affects Apache Traffic Server 8.0.0 to 8.0.8.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:apache:traffic_server:*:*:*:*:*:*:*:* 8.0.0 (including) 8.0.8 (including)
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*