CVE-2025-31698
19.06.2025, 10:15
ACL configured in ip_allow.config or remap.config does not use IP addresses that are provided by PROXY protocol. Users can use a new setting (proxy.config.acl.subjects) to choose which IP addresses to use for the ACL if Apache Traffic Server is configured to accept PROXY protocol. This issue affects undefined: from 10.0.0 through 10.0.6, from 9.0.0 through 9.2.10. Users are recommended to upgrade to version 9.2.11 or 10.0.6, which fixes the issue.Enginsight
Vendor | Product | Version |
---|---|---|
apache | traffic_server | 9.0.0 ≤ 𝑥 < 9.2.11 |
apache | traffic_server | 10.0.0 ≤ 𝑥 < 10.0.6 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Common Weakness Enumeration