CVE-2017-5660
Estado: ModificadaAlta (8.6)—
There is a vulnerability in Apache Traffic Server (ATS) 6.2.0 and prior and 7.0.0 and prior with the Host header and line folding. This can have issues when interacting with upstream proxies and the wrong host being used.
CVSS
- Versión: 3.0
- Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
- Puntuación base: 8.6
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.93%
- Percentil entre todas las CVEs puntuadas: 79
- Fecha de la puntuación: 7/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (2)
CWE
- CWE-20
Referencias
- https://lists.apache.org/thread.html/22d84783d94c53a5132ec89f002fe5165c87561a9428bcb6713b3c98%40%3Cdev.trafficserver.apache.org%3E
- https://www.debian.org/security/2018/dsa-4128
- https://lists.apache.org/thread.html/22d84783d94c53a5132ec89f002fe5165c87561a9428bcb6713b3c98%40%3Cdev.trafficserver.apache.org%3E
- https://www.debian.org/security/2018/dsa-4128
JSON original (NVD)
Mostrar
{
"id": "CVE-2017-5660",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:N/I:P/A:N",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "NONE"
},
"acInsufInfo": true,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV30": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "CHANGED",
"version": "3.0",
"baseScore": 8.6,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 4,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "security@apache.org",
"affectedData": [
{
"vendor": "Apache Software Foundation",
"product": "Apache Traffic Server",
"versions": [
{
"status": "affected",
"version": "6.2.0 and prior"
},
{
"status": "affected",
"version": "7.0.0 and prior"
}
]
}
]
}
],
"published": "2018-02-27T20:29:00.403",
"references": [
{
"url": "https://lists.apache.org/thread.html/22d84783d94c53a5132ec89f002fe5165c87561a9428bcb6713b3c98%40%3Cdev.trafficserver.apache.org%3E",
"source": "security@apache.org"
},
{
"url": "https://www.debian.org/security/2018/dsa-4128",
"tags": [
"Third Party Advisory"
],
"source": "security@apache.org"
},
{
"url": "https://lists.apache.org/thread.html/22d84783d94c53a5132ec89f002fe5165c87561a9428bcb6713b3c98%40%3Cdev.trafficserver.apache.org%3E",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.debian.org/security/2018/dsa-4128",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-20"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "There is a vulnerability in Apache Traffic Server (ATS) 6.2.0 and prior and 7.0.0 and prior with the Host header and line folding. This can have issues when interacting with upstream proxies and the wrong host being used."
},
{
"lang": "es",
"value": "Hay una vulnerabilidad en Apache Traffic Server (ATS) en versiones 6.2.0 y anteriores y versiones 7.0.0 y anteriores con la cabecera Host y el plegado de líneas. Esto puede provocar problemas al interactuar con proxies ascendentes empleando el host erróneo."
}
],
"lastModified": "2026-06-17T01:20:59.157",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:apache:traffic_server:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CE6129F1-1EAD-4000-A691-A062409DEA1B",
"versionEndIncluding": "6.2.0"
},
{
"criteria": "cpe:2.3:a:apache:traffic_server:6.2.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "976F9A2D-B0AC-44B1-A29F-08D9DB7C415D"
},
{
"criteria": "cpe:2.3:a:apache:traffic_server:6.2.1:rc0:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "02670FD4-41D9-4FFC-8E66-C8F2D76977C2"
},
{
"criteria": "cpe:2.3:a:apache:traffic_server:6.2.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "EBFC3680-1EB6-4AAB-A338-D0BB0B18FF72"
},
{
"criteria": "cpe:2.3:a:apache:traffic_server:6.2.2:rc0:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "89019855-BC68-421C-8703-271E859CB5BB"
},
{
"criteria": "cpe:2.3:a:apache:traffic_server:7.0.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "00287C7A-7B52-4917-893E-6BBC83734F0B"
},
{
"criteria": "cpe:2.3:a:apache:traffic_server:7.0.0:rc0:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6FC971C0-5391-42E9-A43C-7EC19C431420"
},
{
"criteria": "cpe:2.3:a:apache:traffic_server:7.0.0:rc1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "20065789-2909-4588-A672-91FE0F6C8C25"
},
{
"criteria": "cpe:2.3:a:apache:traffic_server:7.0.0:rc2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8576A4CE-BF77-4DC8-B3BC-85AC647DD2A1"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "DEECE5FC-CACF-4496-A3E7-164736409252"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security@apache.org"
}