Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Apache Traffic Control: SQL Injection in Traffic Ops endpoint PUT deliveryservice_request_comments
Vulnerability Description
An SQL injection vulnerability in Traffic Ops in Apache Traffic Control <= 8.0.1, >= 8.0.0 allows a privileged user with role "admin", "federation", "operations", "portal", or "steering" to execute arbitrary SQL against the database by sending a specially-crafted PUT request. Users are recommended to upgrade to version Apache Traffic Control 8.0.2 if you run an affected version of Traffic Ops.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Vulnerability Type
SQL命令中使用的特殊元素转义处理不恰当(SQL注入)
Vulnerability Title
Apache Traffic Control 安全漏洞
Vulnerability Description
Apache Traffic Control是美国阿帕奇(Apache)基金会的一套分布式、可扩展的内容分发解决方案。该产品主要用于构建大规模内容分发网络。 Apache Traffic Control存在安全漏洞,该漏洞源于 Traffic Ops 存在 SQL 注入漏洞,允许具有admin、federation、operations、portal或steering角色的特权用户通过发送特制的 PUT 请求对数据库执行任意 SQL。
CVSS Information
N/A
Vulnerability Type
N/A