Skip to main content

Vendor/product archive

apache / traffic_control CVEs

Beta · best-effort

8 CVEs tagged to apache / traffic_control3 Critical, 3 High, 2 Medium, 0 Low, 0 Unrated.

CVE-2025-61581

Published Oct 16, 2025

** UNSUPPORTED WHEN ASSIGNED ** Inefficient Regular Expression Complexity vulnerability in Apache Traffic Control. This issue affects Apache Traffic Control: all versions. Peopl…

CVSS 7.5 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2024-45387

Published Dec 23, 2024

An SQL injection vulnerability in Traffic Ops in Apache Traffic Control <= 8.0.1, >= 8.0.0 allows a privileged user with role "admin", "federation", "operations", "portal", or "st…

CVSS 9.9 · Critical
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2022-23206

Published Feb 6, 2022

In Apache Traffic Control Traffic Ops prior to 6.1.0 or 5.1.6, an unprivileged user who can reach Traffic Ops over HTTPS can send a specially-crafted POST request to /user/login/o…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-43350

Published Nov 11, 2021

An unauthenticated Apache Traffic Control Traffic Ops user can send a request with a specially-crafted username to the POST /login endpoint of any API version to inject unsanitize…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-42009

Published Oct 12, 2021

An authenticated Apache Traffic Control Traffic Ops user with Portal-level privileges can send a request with a specially-crafted email subject to the /deliveryservices/request Tr…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-17522

Published Jan 26, 2021

When ORT (now via atstccfg) generates ip_allow.config files in Apache Traffic Control 3.0.0 to 3.1.0 and 4.0.0 to 4.1.0, those files include permissions that allow bad actors to p…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-12405

Published Sep 9, 2019

Improper authentication is possible in Apache Traffic Control versions 3.0.0 and 3.0.1 if LDAP is enabled for login in the Traffic Ops API component. Given a username for a user t…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-7670

Published Jul 10, 2017

The Traffic Router component of the incubating Apache Traffic Control project is vulnerable to a Slowloris style Denial of Service attack. TCP connections made on the configured D…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-8 of 8 CVEsPage 1 of 1