« Volver al listado

CVE-2017-5660

Estado: ModificadaAlta (8.6)—

There is a vulnerability in Apache Traffic Server (ATS) 6.2.0 and prior and 7.0.0 and prior with the Host header and line folding. This can have issues when interacting with upstream proxies and the wrong host being used.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2017-5660",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": true,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.0",
          "baseScore": 8.6,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 4,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "security@apache.org",
      "affectedData": [
        {
          "vendor": "Apache Software Foundation",
          "product": "Apache Traffic Server",
          "versions": [
            {
              "status": "affected",
              "version": "6.2.0 and prior"
            },
            {
              "status": "affected",
              "version": "7.0.0 and prior"
            }
          ]
        }
      ]
    }
  ],
  "published": "2018-02-27T20:29:00.403",
  "references": [
    {
      "url": "https://lists.apache.org/thread.html/22d84783d94c53a5132ec89f002fe5165c87561a9428bcb6713b3c98%40%3Cdev.trafficserver.apache.org%3E",
      "source": "security@apache.org"
    },
    {
      "url": "https://www.debian.org/security/2018/dsa-4128",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "security@apache.org"
    },
    {
      "url": "https://lists.apache.org/thread.html/22d84783d94c53a5132ec89f002fe5165c87561a9428bcb6713b3c98%40%3Cdev.trafficserver.apache.org%3E",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.debian.org/security/2018/dsa-4128",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-20"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "There is a vulnerability in Apache Traffic Server (ATS) 6.2.0 and prior and 7.0.0 and prior with the Host header and line folding. This can have issues when interacting with upstream proxies and the wrong host being used."
    },
    {
      "lang": "es",
      "value": "Hay una vulnerabilidad en Apache Traffic Server (ATS) en versiones 6.2.0 y anteriores y versiones 7.0.0 y anteriores con la cabecera Host y el plegado de líneas. Esto puede provocar problemas al interactuar con proxies ascendentes empleando el host erróneo."
    }
  ],
  "lastModified": "2026-06-17T01:20:59.157",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:apache:traffic_server:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CE6129F1-1EAD-4000-A691-A062409DEA1B",
              "versionEndIncluding": "6.2.0"
            },
            {
              "criteria": "cpe:2.3:a:apache:traffic_server:6.2.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "976F9A2D-B0AC-44B1-A29F-08D9DB7C415D"
            },
            {
              "criteria": "cpe:2.3:a:apache:traffic_server:6.2.1:rc0:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "02670FD4-41D9-4FFC-8E66-C8F2D76977C2"
            },
            {
              "criteria": "cpe:2.3:a:apache:traffic_server:6.2.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EBFC3680-1EB6-4AAB-A338-D0BB0B18FF72"
            },
            {
              "criteria": "cpe:2.3:a:apache:traffic_server:6.2.2:rc0:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "89019855-BC68-421C-8703-271E859CB5BB"
            },
            {
              "criteria": "cpe:2.3:a:apache:traffic_server:7.0.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "00287C7A-7B52-4917-893E-6BBC83734F0B"
            },
            {
              "criteria": "cpe:2.3:a:apache:traffic_server:7.0.0:rc0:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6FC971C0-5391-42E9-A43C-7EC19C431420"
            },
            {
              "criteria": "cpe:2.3:a:apache:traffic_server:7.0.0:rc1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "20065789-2909-4588-A672-91FE0F6C8C25"
            },
            {
              "criteria": "cpe:2.3:a:apache:traffic_server:7.0.0:rc2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8576A4CE-BF77-4DC8-B3BC-85AC647DD2A1"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DEECE5FC-CACF-4496-A3E7-164736409252"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@apache.org"
}