Rewterz
Rewterz Threat Advisory – Multiple WordPress Plugins Vulnerabilities
June 15, 2023
Rewterz
Rewterz Threat Alert – Russian GRU-Linked APT Group Identified in Data Wiping Attacks – Active IOCs
June 15, 2023

Rewterz Threat Advisory – Multiple Apache Traffic Server Vulnerabilities

Severity

High

Analysis Summary

CVE-2023-33933 CVSS:5.3

Apache Traffic Server could allow a remote attacker to obtain sensitive information, caused by an s3_auth plugin problem with hash calculation. An attacker could exploit this vulnerability to obtain sensitive information.

CVE-2022-47184 CVSS:5.3

Apache Traffic Server could allow a remote attacker to obtain sensitive information, caused by the exposure of sensitive information to an unauthorized actor vulnerability. An attacker could exploit this vulnerability using the TRACE method to disclose network information.

Impact

  • Information Disclosure

Indicators Of Compromise

CVE

  • CVE-2023-33933
  • CVE-2022-47184

Affected Vendors

Apache

Affected Products

  • Apache Traffic Server 8.0.0
  • Apache Traffic Server 9.0.0
  • Apache Traffic Server 8.1.4
  • Apache Traffic Server 9.1.2

Remediation

Upgrade to the latest version of Apache Traffic Server, available from the Apache Website. 

CVE-2023-33933

CVE-2022-47184