CyberRota Analysis
AI-GeneratedApache Traffic Server versions 9.0.0 to 9.2.14 and 10.0.0 to 10.1.3 are vulnerable due to improper verification of server certificates when reusing multiplexed HTTP/2 origin connections, potentially allowing man-in-the-middle attacks. This could lead to unauthorized access or data interception for requests directed to different hostnames. Organizations using affected versions should prioritize upgrading to 9.2.15 or 10.1.4 to mitigate this risk.
Original NVD Description
Apache Traffic Server reuses multiplexed HTTP/2 origin connections without verifying the server certificate covers the new request hostname. This issue affects Apache Traffic Server: from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
Related CVEs
Other vulnerabilities affecting the same vendor(s)