Apache Traffic Server is an OpenSource HTTP / HTTPS / HTTP/2 / QUIC reverse,forward and transparent proxy and cache.
Security Fix(es):
Improper Check for Unusual or Exceptional Conditions vulnerability handling requests in Apache Traffic Server allows an attacker to crash the server under certain conditions. This issue affects Apache Traffic Server: from 8.0.0 through 9.1.3.(CVE-2022-32749)
Improper Check for Unusual or Exceptional Conditions vulnerability in handling the requests to Apache Traffic Server. This issue affects Apache Traffic Server 8.0.0 to 9.1.2.(CVE-2022-37392)
Improper Input Validation vulnerability for the xdebug plugin in Apache Software Foundation Apache Traffic Server can lead to cross site scripting and cache poisoning attacks.This issue affects Apache Traffic Server: 9.0.0 to 9.1.3. Users should upgrade to 9.1.4 or later versions.(CVE-2022-40743)
{ "severity": "High" }
{ "aarch64": [ "trafficserver-devel-9.1.4-1.oe1.aarch64.rpm", "trafficserver-debuginfo-9.1.4-1.oe1.aarch64.rpm", "trafficserver-perl-9.1.4-1.oe1.aarch64.rpm", "trafficserver-9.1.4-1.oe1.aarch64.rpm", "trafficserver-debugsource-9.1.4-1.oe1.aarch64.rpm" ], "src": [ "trafficserver-9.1.4-1.oe1.src.rpm" ], "x86_64": [ "trafficserver-debuginfo-9.1.4-1.oe1.x86_64.rpm", "trafficserver-9.1.4-1.oe1.x86_64.rpm", "trafficserver-devel-9.1.4-1.oe1.x86_64.rpm", "trafficserver-perl-9.1.4-1.oe1.x86_64.rpm", "trafficserver-debugsource-9.1.4-1.oe1.x86_64.rpm" ] }