Medium severity5.8OSV Advisory· Published Jan 26, 2021· Updated Jun 17, 2026
CVE-2020-17522
CVE-2020-17522
Description
When ORT (now via atstccfg) generates ip_allow.config files in Apache Traffic Control 3.0.0 to 3.1.0 and 4.0.0 to 4.1.0, those files include permissions that allow bad actors to push arbitrary content into and remove arbitrary content from CDN cache servers. Additionally, these permissions are potentially extended to IP addresses outside the desired range, resulting in them being granted to clients possibly outside the CDN arcitechture.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/apache/trafficcontrolGo | < 5.0.0 | 5.0.0 |
Affected products
3- Range: RELEASE-3.0.0, RELEASE-3.0.0-RC6, RELEASE-3.0.1, …
Patches
Vulnerability mechanics
References
8- github.com/advisories/GHSA-pw59-4qgf-jxr8ghsaADVISORY
- lists.apache.org/thread.html/r3de212a3da73bcf98fa2db7eafb75b2eb8e131ff466e6efc4284df09%40%3Cdev.trafficcontrol.apache.org%3EnvdMailing ListVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2020-17522ghsaADVISORY
- github.com/apache/trafficcontrol/commit/492290d810e9608afb5d265b98cd3f3e153e776bghsaWEB
- lists.apache.org/thread.html/r3c675031ac220b5eae64a9c84a03ee60045c6045738607dca4a96cb8@%3Ccommits.trafficcontrol.apache.org%3EghsaWEB
- lists.apache.org/thread.html/rc8bfd7d4f71d61e9193efcd4699eccbab3c202ec1d75ed9d502f08bf@%3Ccommits.trafficcontrol.apache.org%3EghsaWEB
- lists.apache.org/thread.html/r3c675031ac220b5eae64a9c84a03ee60045c6045738607dca4a96cb8%40%3Ccommits.trafficcontrol.apache.org%3Envd
- lists.apache.org/thread.html/rc8bfd7d4f71d61e9193efcd4699eccbab3c202ec1d75ed9d502f08bf%40%3Ccommits.trafficcontrol.apache.org%3Envd
News mentions
0No linked articles in our index yet.