Vulnerability Description
sslheaders plugin extracts information from the client certificate and sets headers in the request based on the configuration of the plugin. The plugin doesn't strip the headers from the request in some scenarios. This problem was discovered in versions 6.0.0 to 6.0.3, 7.0.0 to 7.1.5, and 8.0.0 to 8.0.1.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Traffic Server | >= 6.0.0, <= 6.0.3 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/107032Third Party Advisory
- https://lists.apache.org/thread.html/4f102f943935476732fb1fb653d687c7b69d29d9792
- http://www.securityfocus.com/bid/107032Third Party Advisory
- https://lists.apache.org/thread.html/4f102f943935476732fb1fb653d687c7b69d29d9792
FAQ
What is CVE-2018-11783?
CVE-2018-11783 is a vulnerability with a CVSS score of 7.5 (HIGH). sslheaders plugin extracts information from the client certificate and sets headers in the request based on the configuration of the plugin. The plugin doesn't strip the headers from the request in so...
How severe is CVE-2018-11783?
CVE-2018-11783 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-11783?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Traffic Server.