CVE-2020-17508

HIGH

Apache Traffic Server <8.2 - Info Disclosure

Title source: llm
STIX 2.1

Description

The ATS ESI plugin has a memory disclosure vulnerability. If you are running the plugin please upgrade. Apache Traffic Server versions 7.0.0 to 7.1.11 and 8.0.0 to 8.1.0 are affected.

Scores

CVSS v3 7.5
EPSS 0.0266
EPSS Percentile 86.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

Status published
Products (1)
apache/traffic_server 6.0.0 - 6.2.3
Published Jan 11, 2021
Tracked Since Feb 18, 2026