CVE-2022-47184

Source
https://cve.org/CVERecord?id=CVE-2022-47184
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-47184.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2022-47184
Downstream
Published
2023-06-14T07:42:36.126Z
Modified
2026-05-18T05:55:49.237288265Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
Apache Traffic Server: The TRACE method can be use to disclose network information
Details

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache Traffic Server.This issue affects Apache Traffic Server: 8.0.0 to 9.2.0.

Database specific
{
    "cwe_ids": [
        "CWE-200"
    ],
    "cna_assigner": "apache",
    "unresolved_ranges": [
        {
            "source": "AFFECTED_FIELD",
            "extracted_events": [
                {
                    "introduced": "8.0.0"
                },
                {
                    "last_affected": "9.2.0"
                }
            ]
        }
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/47xxx/CVE-2022-47184.json"
}
References

Affected packages

Git / github.com/apache/trafficserver

Affected ranges

Type
GIT
Repo
https://github.com/apache/trafficserver
Events
Database specific
{
    "cpe": "cpe:2.3:a:apache:traffic_server:*:*:*:*:*:*:*:*",
    "source": "CPE_FIELD",
    "extracted_events": [
        {
            "introduced": "8.0.0"
        },
        {
            "fixed": "8.1.7"
        },
        {
            "introduced": "9.0.0"
        },
        {
            "fixed": "9.2.1"
        }
    ]
}

Affected versions

8.*
8.0.0
8.0.0-rc4
8.0.1
8.0.1-rc0
8.0.2
8.0.2-rc0
8.0.3
8.0.3-rc0
8.0.4
8.0.4-rc0
8.0.5
8.0.6
8.0.6-rc0
8.0.6-rc1
8.1.0
8.1.0-rc0
8.1.1
8.1.1-rc0
8.1.2-rc0
8.1.3
8.1.3-rc0
8.1.3-rc1
8.1.4
8.1.4-rc0
8.1.5
8.1.5-rc0
8.1.6
8.1.6-rc0

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-47184.json"