CVE-2020-17509

HIGH

Apache Traffic Server <8.1.0 - Cache Poisoning

Title source: llm
STIX 2.1

Description

ATS negative cache option is vulnerable to a cache poisoning attack. If you have this option enabled, please upgrade or disable this feature. Apache Traffic Server versions 7.0.0 to 7.1.11 and 8.0.0 to 8.1.0 are affected.

Scores

CVSS v3 7.5
EPSS 0.0305
EPSS Percentile 86.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Details

CWE
CWE-444
Status published
Products (1)
apache/traffic_server 6.0.0 - 6.2.3
Published Jan 11, 2021
Tracked Since Feb 18, 2026