Apache / Traffic Control
8 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2025-61581 | Apache Traffic Control: ReDoS issue in Traffic Router configuration | LOW | 1.3 | Oct 16, 2025 |
| CVE-2024-45387 | Apache Traffic Control: SQL Injection in Traffic Ops endpoint PUT deliveryservice_request_comments | CRITICAL | 9.9 | Dec 23, 2024 |
| CVE-2022-23206 | Server-Side Request Forgery in Traffic Ops endpoint POST /user/login/oauth | HIGH | 7.5 | Feb 6, 2022 |
| CVE-2021-43350 | LDAP filter injection vulnerability in Traffic Ops | CRITICAL | 9.8 | Nov 11, 2021 |
| CVE-2021-42009 | Apache Traffic Control Traffic Ops Email Injection Vulnerability | MEDIUM | 4.3 | Oct 12, 2021 |
| CVE-2020-17522 | When ORT (now via atstccfg) generates ip_allow.config files in Apache Traffic Control 3.0.0 to 3.1.0 and 4.0.0 to 4.1.0, those files include permissions that a… | MEDIUM | 5.8 | Jan 26, 2021 |
| CVE-2019-12405 | Improper authentication is possible in Apache Traffic Control versions 3.0.0 and 3.0.1 if LDAP is enabled for login in the Traffic Ops API component. Given a u… | CRITICAL | 9.8 | Sep 9, 2019 |
| CVE-2017-7670 | The Traffic Router component of the incubating Apache Traffic Control project is vulnerable to a Slowloris style Denial of Service attack. TCP connections made… | HIGH | 7.5 | Jul 10, 2017 |
Showing 1 to 8 of 8 CVEs