HIGH🇬🇧 English

CVE-2025-61581

CVSS 7.5v3.1pub. 2025-10-16upd. 2025-11-04

** UNSUPPORTED WHEN ASSIGNED ** Inefficient Regular Expression Complexity vulnerability in Apache Traffic Control. This issue affects Apache Traffic Control: all versions. People with access to the management interface of the Traffic Router component could specify malicious patterns and cause unavailability. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

oryginał EN
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  • Apache Traffic Control

    APP
    Apache
    ≤ 8.0.2
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
CWE
Referencje

Powiązane podatności

CVE-2024-45387CRITICAL9.9PL ✓ten sam produkt

SQL injection w Apache Traffic Control — eskalacja uprawnień przez Traffic Ops

CVE-2021-43350CRITICAL9.8PL ✓ten sam produkt

Apache Traffic Control Traffic Ops — LDAP injection w endpoincie logowania

CVE-2019-12405CRITICAL9.8PL ✓ten sam produkt

Apache Traffic Control — pominięcie uwierzytelnienia LDAP w Traffic Ops API

CVE-2022-23206HIGH7.5ten sam produkt

In Apache Traffic Control Traffic Ops prior to 6.1.0 or 5.1.6, an unprivileged user who can reach Traffic Ops ...

CVE-2017-7670HIGH7.5ten sam produkt

The Traffic Router component of the incubating Apache Traffic Control project is vulnerable to a Slowloris sty...