CVE-2021-32565
EUVD-2021-1940729.06.2021, 12:15
Invalid values in the Content-Length header sent to Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache Traffic Server 7.0.0 to 7.1.12, 8.0.0 to 8.1.1, 9.0.0 to 9.0.1.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| apache | traffic_server | 7.0.0 ≤ 𝑥 ≤ 7.1.12 |
| apache | traffic_server | 8.0.0 ≤ 𝑥 ≤ 8.1.1 |
| apache | traffic_server | 9.0.0 ≤ 𝑥 ≤ 9.0.1 |
| debian | debian_linux | 10.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
References