VYPR
High severity8.1NVD Advisory· Published Nov 3, 2021· Updated Jun 17, 2026

CVE-2021-38161

CVE-2021-38161

Description

Improper Authentication vulnerability in TLS origin verification of Apache Traffic Server allows for man in the middle attacks. This issue affects Apache Traffic Server 8.0.0 to 8.0.8.

Affected products

5
  • cpe:2.3:a:apache:traffic_server:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:apache:traffic_server:*:*:*:*:*:*:*:*range: >=8.0.0,<=8.0.8
    • (no CPE)range: 8.0.0 - 8.0.8
    • (no CPE)range: 8.0.0 to 8.0.8
  • Debian/linux2 versions
    cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
    • cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.