Description
Apache Traffic Server allows redirect-limit bypass when plugins reset the retry counter, enabling SSRF amplification. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
Remediation
References
Related Vulnerabilities
Apache Traffic Server Uncontrolled Resource Consumption Vulnerability (CVE-2018-8005)
WordPress Plugin Like Button Rating-LikeBtn Server-Side Request Forgery (2.6.31)
WordPress Plugin NextScripts:Social Networks Auto-Poster Cross-Site Scripting (4.3.20)
Moodle Improper Input Validation Vulnerability (CVE-2019-10134)