Candidate: CVE-2021-37147 PublicDate: 2021-11-03 16:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-37147 https://www.openwall.com/lists/oss-security/2021/11/02/11 https://github.com/apache/trafficserver/commit/64f25678bfbbd1433cce703e3c43bcc49a53de56 (master) https://github.com/apache/trafficserver/commit/5cad961c87cb07fbb8fa6890685d9878a169378d (8.1.x) https://github.com/apache/trafficserver/pull/8460 Description: Improper input validation vulnerability in header parsing of Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache Traffic Server 8.0.0 to 8.1.2 and 9.0.0 to 9.1.0. Ubuntu-Description: Notes: Mitigation: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N [7.5 HIGH] Patches_trafficserver: upstream_trafficserver: needs-triage trusty_trafficserver: ignored (out of standard support) xenial_trafficserver: ignored (out of standard support) bionic_trafficserver: needs-triage focal_trafficserver: needs-triage hirsute_trafficserver: ignored (reached end-of-life) impish_trafficserver: needs-triage jammy_trafficserver: needs-triage devel_trafficserver: needs-triage