VYPR
High severity7.5NVD Advisory· Published Jun 29, 2021· Updated Jun 17, 2026

CVE-2021-27577

CVE-2021-27577

Description

Incorrect handling of url fragment vulnerability of Apache Traffic Server allows an attacker to poison the cache. This issue affects Apache Traffic Server 7.0.0 to 7.1.12, 8.0.0 to 8.1.1, 9.0.0 to 9.0.1.

Affected products

4
  • cpe:2.3:a:apache:traffic_server:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:apache:traffic_server:*:*:*:*:*:*:*:*range: >=7.0.0,<=7.1.12
    • (no CPE)range: 7.0.0-7.1.12, 8.0.0-8.1.1, 9.0.0-9.0.1
    • (no CPE)range: Apache Traffic Server 7.0.0 to 7.1.12, 8.0.0 to 8.1.1, 9.0.0 to 9.0.1
  • cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.