CVE-2022-40743

MEDIUM

Apache Traffic Server 9.0.0-9.1.3 - Cross-Site Scripting and Cache Poisoning via xdebug Plugin

Title source: llm
STIX 2.1

Description

Improper Input Validation vulnerability for the xdebug plugin in Apache Software Foundation Apache Traffic Server can lead to cross site scripting and cache poisoning attacks.This issue affects Apache Traffic Server: 9.0.0 to 9.1.3. Users should upgrade to 9.1.4 or later versions.

References (1)

Core 1
Core References
Mailing List, Vendor Advisory vendor-advisory
https://lists.apache.org/thread/mrj2lg4s0hf027rk7gz8t7hbn9xpfg02

Scores

CVSS v3 6.1
EPSS 0.0823
EPSS Percentile 92.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (1)
apache/traffic_server 8.0.0 - 8.1.5
Published Dec 19, 2022
Tracked Since Feb 18, 2026