Rewterz

Rewterz Threat Advisory – Multiple WordPress Plugins Vulnerabilities

June 15, 2023
Rewterz

Rewterz Threat Alert – Russian GRU-Linked APT Group Identified in Data Wiping Attacks – Active IOCs

June 15, 2023

Rewterz Threat Advisory – Multiple Apache Traffic Server Vulnerabilities

Severity

High

Analysis Summary

CVE-2023-33933 CVSS:5.3

Apache Traffic Server could allow a remote attacker to obtain sensitive information, caused by an s3_auth plugin problem with hash calculation. An attacker could exploit this vulnerability to obtain sensitive information.

CVE-2022-47184 CVSS:5.3

Apache Traffic Server could allow a remote attacker to obtain sensitive information, caused by the exposure of sensitive information to an unauthorized actor vulnerability. An attacker could exploit this vulnerability using the TRACE method to disclose network information.

Impact

  • Information Disclosure

Indicators Of Compromise

CVE

  • CVE-2023-33933
  • CVE-2022-47184

Affected Vendors

Apache

Affected Products

  • Apache Traffic Server 8.0.0
  • Apache Traffic Server 9.0.0
  • Apache Traffic Server 8.1.4
  • Apache Traffic Server 9.1.2

Remediation

Upgrade to the latest version of Apache Traffic Server, available from the Apache Website. 

CVE-2023-33933

CVE-2022-47184

Reading this advisory was a good start.

Make it a habit.

Rewterz publishes threat advisories ahead of mainstream cybersecurity media, informed by an AI-Native Autonomous SOC that sees regional threat actor activity in real time. Subscribe to receive each new advisory as it publishes, plus a monthly Middle East threat landscape brief drawn from our own SOC telemetry. For teams evaluating their detection coverage, a 30-minute consultation with a senior analyst is also available, at your pace, when you're ready.