CVE-2024-45387
Apache Traffic Control: SQL Injection in Traffic Ops endpoint PUT deliveryservice_request_comments
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
An SQL injection vulnerability in Traffic Ops in Apache Traffic Control <= 8.0.1, >= 8.0.0 allows a privileged user with role "admin", "federation", "operations", "portal", or "steering" to execute arbitrary SQL against the database by sending a specially-crafted PUT request. Users are recommended to upgrade to version Apache Traffic Control 8.0.2 if you run an affected version of Traffic Ops.
Una vulnerabilidad de inyección SQL en Traffic Ops en Apache Traffic Control <= 8.0.1, >= 8.0.0 permite que un usuario privilegiado con el rol "admin", "federación", "operaciones", "portal" o "dirección" ejecute SQL arbitrario contra la base de datos enviando una solicitud PUT especialmente manipulada. Se recomienda a los usuarios actualizar a la versión Apache Traffic Control 8.0.2 si ejecutan una versión afectada de Traffic Ops.
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2024-08-28 CVE Reserved
- 2024-12-23 CVE Published
- 2024-12-24 CVE Updated
- 2025-04-16 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
- CWE-285: Improper Authorization
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
http://www.openwall.com/lists/oss-security/2024/12/23/3 |
|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://lists.apache.org/thread/t38nk5n7t8w3pb66z7z4pqfzt4443trr | 2024-12-23 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Apache Software Foundation Search vendor "Apache Software Foundation" | Apache Traffic Control Search vendor "Apache Software Foundation" for product "Apache Traffic Control" | >= 8.0.0 <= 8.0.1 Search vendor "Apache Software Foundation" for product "Apache Traffic Control" and version " >= 8.0.0 <= 8.0.1" | en |
Affected
|