CRITICAL🇵🇱 Wersja polska

CVE-2024-50306

CVSS 9.1v3.1pub. 2024-11-14upd. 2025-11-03

Unchecked return value can allow Apache Traffic Server to retain privileges on startup. This issue affects Apache Traffic Server: from 9.2.0 through 9.2.5, from 10.0.0 through 10.0.1. Users are recommended to upgrade to version 9.2.6 or 10.0.2, which fixes the issue.

🤖 AI Analysis
How it works

During startup, Apache Traffic Server should drop its privileges (privilege drop) to the level of a regular user. Due to failure to verify the return value from the appropriate system function, this operation may fail without the application detecting the error. As a result, the server process continues to operate with retained elevated privileges instead of limited ones. An attacker who can influence the server's operation can consequently gain broader access to the system.

Impact

An attacker can exploit the fact that the server operates with elevated privileges to modify critical system resources (integrity violation) or disrupt its operation (availability violation). A network vector without authentication requirement increases the risk of remote exploitation.

Mitigation & patch

Apache Traffic Server should be updated to version 9.2.6 (for the 9.x branch) or 10.0.2 (for the 10.x branch), which contain patches eliminating the vulnerability.

Who is affected

Apache Traffic Server in versions from 9.2.0 to 9.2.5 and from 10.0.0 to 10.0.1

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
  • Apache Traffic Server

    APP
    Apache
    9.0.0 – 9.2.6 (excl.)10.0.0 – 10.0.2 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2026-58179CRITICAL9.2PL ✓same product

Apache Traffic Server: przepełnienie stosu w pluginie regex_remap

CVE-2026-58154CRITICAL9.2PL ✓same product

Apache Traffic Server — zapis poza granicami bufora przy parsowaniu nagłówków MIME/HTTP

CVE-2026-58161CRITICAL9.2PL ✓same product

Apache Traffic Server — crash przez null dereference w obsłudze TLS/SNI

CVE-2026-58155CRITICAL9.2PL ✓same product

Apache Traffic Server — request smuggling przez obcinanie nazw nagłówków

CVE-2023-33934CRITICAL9.1PL ✓same product

Apache Traffic Server — nieprawidłowa walidacja danych wejściowych (HTTP smuggling)