CyberRota Analysis
AI-GeneratedThe Apache Traffic Server certifier plugin is vulnerable due to its ability to generate certificates based on attacker-controlled client SNI, potentially allowing unauthorized access or man-in-the-middle attacks. This critical vulnerability impacts versions 8.0.0 to 8.1.9, 9.0.0 to 9.2.14, and 10.0.0 to 10.1.3, necessitating immediate attention from organizations using these versions. Users should prioritize upgrading to version 9.2.15 or 10.1.4 to mitigate the risk.
Original NVD Description
The Apache Traffic Server certifier plugin generates certificates based on attacker-controlled client SNI. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
Related CVEs
Other vulnerabilities affecting the same vendor(s)