VDB
CVE-2017-5660
CVE-2017-5660
PUBLISHED
There is a vulnerability in Apache Traffic Server (ATS) 6.2.0 and prior and 7.0.0 and prior with the Host header and line folding. This can have issues when interacting with upstream proxies and the wrong host being used.
EPSS 1.93% · 78.5th percentile
Risk Scores
EPSS Score
1.93%
78.5th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ubuntu:16.04:LTS | trafficserver | 5.3.0-2ubuntu1, 5.3.0-2ubuntu2, 0 |
Timeline
- Feb 27, 2018 CVE Published
- Apr 14, 2021 EPSS Score
- Jun 23, 2021 EPSS Score
- Oct 26, 2021 EPSS Score
- Dec 28, 2021 EPSS Score
- Feb 28, 2022 EPSS Score
- May 2, 2022 EPSS Score
- Jul 4, 2022 EPSS Score
- Nov 7, 2022 EPSS Score
- Jan 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- May 14, 2023 EPSS Score
References
- https://ubuntu.com/security/CVE-2017-5660 third-party-advisory
- https://github.com/apache/trafficserver/pull/1657 third-party-advisory
- https://lists.apache.org/thread.html/22d84783d94c53a5132ec89f002fe5165c87561a9428bcb6713b3c98@%3Cdev.trafficserver.apache.org%3E third-party-advisory
- https://www.cve.org/CVERecord?id=CVE-2017-5660 third-party-advisory