imPC@ndo IT

Tracker / CVE-2024-35296

CVE-2024-35296

High 8.2

Invalid Accept-Encoding header can cause Apache Traffic Server to fail cache lookup and force forwarding requests. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.10, from 9.0.0 through 9.2.4. Users are recommended to upgrade to version 8.1.11 or 9.2.5, which fixes the issue.

Affected products and versions

apache traffic_server · 8.0.0 → 8.1.11
apache traffic_server · 9.0.0 → 9.2.5

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References