apache traffic-control CVE-2021-42009 is a vulnerability in Apache Traffic Control
Published on October 12, 2021

Apache Traffic Control Traffic Ops Email Injection Vulnerability
An authenticated Apache Traffic Control Traffic Ops user with Portal-level privileges can send a request with a specially-crafted email subject to the /deliveryservices/request Traffic Ops endpoint to send an email, from the Traffic Ops server, with an arbitrary body to an arbitrary email address. Apache Traffic Control 5.1.x users should upgrade to 5.1.3 or 6.0.0. 4.1.x users should upgrade to 5.1.3.

NVD

Weakness Type

Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.


Products Associated with CVE-2021-42009

You can be notified by email with stack.watch whenever vulnerabilities like CVE-2021-42009 are published in Apache Traffic Control:

 

Affected Versions

Apache Software Foundation Apache Traffic Control:

Exploit Probability

EPSS
0.65%
Percentile
70.50%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.