CVE-2014-3624
9.8
CRITICAL · CVSS 3.0 · EPSS 3.8% (pctl 90)
In your normal cycle
Critical by CVSS (9.8), but no sign of active exploitation.
Description
Apache Traffic Server 5.1.x before 5.1.1 allows remote attackers to bypass access restrictions by leveraging failure to properly tunnel remap requests using CONNECT.
Scoring
| CVSS | 9.8 (CRITICAL, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 3.77% — more likely to be exploited than 90% of all CVEs |
| Weakness | CWE-284 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2017-10-30 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| apache | traffic server |
References
- http://mail-archives.apache.org/mod_mbox/www-announce/201411.mbox/%3C20141101231749.2E3561043F%40minotaur.apache.org%3E
- http://www.securityfocus.com/bid/101630
- https://issues.apache.org/jira/browse/TS-2677
- http://mail-archives.apache.org/mod_mbox/www-announce/201411.mbox/%3C20141101231749.2E3561043F%40minotaur.apache.org%3E
- http://www.securityfocus.com/bid/101630
- https://issues.apache.org/jira/browse/TS-2677
→ the Explorer · watch your stack · NVD