VYPR
High severity7.5NVD Advisory· Published Feb 6, 2022· Updated Jun 17, 2026

CVE-2022-23206

CVE-2022-23206

Description

In Apache Traffic Control Traffic Ops prior to 6.1.0 or 5.1.6, an unprivileged user who can reach Traffic Ops over HTTPS can send a specially-crafted POST request to /user/login/oauth to scan a port of a server that Traffic Ops can reach.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
github.com/apache/trafficcontrolGo
>= 6.0.0, < 6.1.06.1.0
github.com/apache/trafficcontrolGo
< 5.1.65.1.6

Affected products

3

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.