Candidate: CVE-2021-38161 PublicDate: 2021-11-03 16:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-38161 https://www.openwall.com/lists/oss-security/2021/11/02/11 https://github.com/apache/trafficserver/commit/feefc5e4abc5011dfad5dcfef3f22998faf6e2d4 (8.1.x) Description: Improper Authentication vulnerability in TLS origin verification of Apache Traffic Server allows for man in the middle attacks. This issue affects Apache Traffic Server 8.0.0 to 8.0.8. Ubuntu-Description: Notes: Mitigation: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H [8.1 HIGH] Patches_trafficserver: upstream_trafficserver: released (9.1.0+ds-1) trusty_trafficserver: ignored (out of standard support) xenial_trafficserver: ignored (out of standard support) bionic_trafficserver: needs-triage focal_trafficserver: needs-triage hirsute_trafficserver: ignored (reached end-of-life) impish_trafficserver: needs-triage jammy_trafficserver: needs-triage devel_trafficserver: needs-triage