Unchecked return value can allow Apache Traffic Server to retain privileges on startup. This issue affects Apache Traffic Server: from 9.2.0 through 9.2.5, from 10.0.0 through 10.0.1. Users are recommended to upgrade to version 9.2.6 or 10.0.2, which fixes the issue.
During startup, Apache Traffic Server should drop its privileges (privilege drop) to the level of a regular user. Due to failure to verify the return value from the appropriate system function, this operation may fail without the application detecting the error. As a result, the server process continues to operate with retained elevated privileges instead of limited ones. An attacker who can influence the server's operation can consequently gain broader access to the system.
An attacker can exploit the fact that the server operates with elevated privileges to modify critical system resources (integrity violation) or disrupt its operation (availability violation). A network vector without authentication requirement increases the risk of remote exploitation.
Apache Traffic Server should be updated to version 9.2.6 (for the 9.x branch) or 10.0.2 (for the 10.x branch), which contain patches eliminating the vulnerability.
Apache Traffic Server in versions from 9.2.0 to 9.2.5 and from 10.0.0 to 10.0.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:HApache Traffic Server
APPApache9.0.0 – 9.2.6 (excl.)10.0.0 – 10.0.2 (excl.)
Related vulnerabilities
Apache Traffic Server: przepełnienie stosu w pluginie regex_remap
Apache Traffic Server — zapis poza granicami bufora przy parsowaniu nagłówków MIME/HTTP
Apache Traffic Server — crash przez null dereference w obsłudze TLS/SNI
Apache Traffic Server — request smuggling przez obcinanie nazw nagłówków
Apache Traffic Server — nieprawidłowa walidacja danych wejściowych (HTTP smuggling)