VDB

CVE-2021-32567

CVE-2021-32567 PUBLISHED CVSS 7.5 HIGH

Improper Input Validation vulnerability in HTTP/2 of Apache Traffic Server allows an attacker to DOS the server. This issue affects Apache Traffic Server 7.0.0 to 7.1.12, 8.0.0 to 8.1.1, 9.0.0 to 9.0.1.

EPSS 2.45% · 83.8th percentile

Risk Scores

CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
2.45%
83.8th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTStrafficserver0, 5.3.0-2ubuntu2, 5.3.0-2ubuntu1
Ubuntu:18.04:LTStrafficserver0, 7.1.2+ds-2build1, 7.1.2+ds-3
Ubuntu:Pro:20.04:LTStrafficserver8.0.5+ds-2, 8.0.5+ds-2ubuntu1, 8.0.5+ds-2build1

Timeline

  • Jun 30, 2021 EPSS Score
  • Jun 30, 2021 CVE Published
  • Aug 15, 2021 EPSS Score
  • Aug 29, 2021 EPSS Score
  • Dec 28, 2021 EPSS Score
  • Feb 4, 2022 EPSS Score
  • Feb 27, 2022 EPSS Score
  • Apr 28, 2022 EPSS Score
  • Aug 28, 2022 EPSS Score
  • Dec 26, 2022 EPSS Score
  • Feb 25, 2023 EPSS Score
  • Apr 26, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›