Tag: Apache Software Foundation (ASF)

Critical SQL Injection Vulnerability in Apache Traffic Control Rated 9.9 CVSS — Patch Now
News

Critical SQL Injection Vulnerability in Apache Traffic Control Rated 9.9 CVSS — Patch Now

To fix a serious security vulnerability in Traffic Control that, if properly exploited, may enable an attacker to run arbitrary Structured Query Language (SQL) instructions in the database, the Apache Software Foundation (ASF) has released security upgrades. On the CVSS scoring system, the SQL injection vulnerability, identified as CVE-2024-45387, has a rating of 9.9 out of 10.0. "A privileged user with the role 'admin,' 'federation,' 'operations,' 'portal,' or'steering' can execute arbitrary SQL against the database by sending a specially-crafted PUT request," according to an advisory from project maintainers regarding a SQL injection vulnerability in Traffic Ops in Apache Traffic Control <= 8.0.1, >= 8.0.0. One open-source implementation of a content delivery network (CDN...