CVE-2024-50306

CRITICAL

Apache Traffic Server <9.2.6, <10.0.2 - Privilege Escalation

Title source: llm
STIX 2.1

Description

Unchecked return value can allow Apache Traffic Server to retain privileges on startup. This issue affects Apache Traffic Server: from 9.2.0 through 9.2.5, from 10.0.0 through 10.0.1. Users are recommended to upgrade to version 9.2.6 or 10.0.2, which fixes the issue.

Scores

CVSS v3 9.1
EPSS 0.0082
EPSS Percentile 74.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-252
Status published
Products (2)
apache/traffic_server 10.0.0 - 10.0.2
apache/traffic_server 9.0.0 - 9.2.6
Published Nov 14, 2024
Tracked Since Feb 18, 2026