CVE-2024-45387

CRITICAL

Apache Traffic Control <=8.0.1, >=8.0.0 - SQL Injection

Title source: llm

Description

An SQL injection vulnerability in Traffic Ops in Apache Traffic Control <= 8.0.1, >= 8.0.0 allows a privileged user with role "admin", "federation", "operations", "portal", or "steering" to execute arbitrary SQL against the database by sending a specially-crafted PUT request. Users are recommended to upgrade to version Apache Traffic Control 8.0.2 if you run an affected version of Traffic Ops.

Scores

CVSS v3 9.9
EPSS 0.4073
EPSS Percentile 97.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Classification

CWE
CWE-285 CWE-89
Status published

Affected Products (2)

apache/traffic_control < 8.0.2
apache/trafficcontrol < 8.0.2Go

Timeline

Published Dec 23, 2024
Tracked Since Feb 18, 2026