CVE-2021-32565

7.5HIGH

Invalid values in the Content-Length header sent to Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache Traffic Server 7.0.0 to 7.1.12, 8.0.0 to 8.1.1, 9.0.0 to 9.0

Published: 6/29/2021Updated: 11/21/2024

Description

Invalid values in the Content-Length header sent to Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache Traffic Server 7.0.0 to 7.1.12, 8.0.0 to 8.1.1, 9.0.0 to 9.0.1.

AI AnalysisPowered by AI

Affected Products

apachetraffic_server
apachetraffic_server
apachetraffic_server
debiandebian_linux
10.0

References