Description
Apache Traffic Server mis-parses ports in URLs and userinfo, allowing port-based access-control bypass. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
Remediation
References
Related Vulnerabilities
WebLogic CVE-2020-2829 Vulnerability (CVE-2020-2829)
WordPress 4.1.x Multiple Vulnerabilities (4.1 - 4.1.31)
MySQL CVE-2015-0505 Vulnerability (CVE-2015-0505)
WordPress Plugin VideoWhisper Video Presentation 'vw_upload.php' Arbitrary File Upload (3.17)
Jboss EAP Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2010-3878)