Apache fixed a critical SQL Injection in Apache Traffic Control

Share:

Apache Software Foundation (ASF) addressed a critical SQL Injection vulnerability, tracked as CVE-2024-45387, in Apache Traffic Control.

The Apache Software Foundation (ASF) released security updates to address a critical security vulnerability, tracked as CVE-2024-45387 (CVSS score 9.9), in Traffic Control.

Traffic Control allows operators to set up a Content Delivery Network to quickly and efficiently deliver content to their users. Traffic Control is a highly distributed, scalable and redundant solution meeting the needs of operators from small to large.

The flaw is an SQL injection vulnerability in Traffic Control (<= 8.0.1, >= 8.0.0), it allows privileged users to execute arbitrary SQL commands.

“An SQL injection vulnerability in Traffic Ops in Apache Traffic Control <= 8.0.1, >= 8.0.0 allows a privileged user with role “admin”, “federation”, “operations”, “portal”, or “steering” to execute arbitrary SQL against the database by sending a specially-crafted PUT request.” reads the advisory. “Users are recommended to upgrade to version Apache Traffic Control 8.0.2 if you run an affected version of Traffic Ops.”

Traffic Control 7.0.0 before 8.0.0 are not affected by this vulnerability.

The researchers Yuan Luo from Tencent YunDing Security Lab reported the vulnerability.

Early this month, The Apache Software Foundation released a security update to address a “possible remote code execution” flaw in Struts 2 that is related to the OGNL technology.

The remote code execution flaw, tracked as CVE-2020-17530, resides in forced OGNL evaluation when evaluated on raw user input in tag attributes.

Source

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
7:15 pm, May 17, 2025
weather icon 18°C
L: 18° | H: 20°
clear sky
Humidity: 52 %
Pressure: 1021 mb
Wind: 2 mph NNW
Wind Gust: 4 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 0%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 5:05 am
Sunset: 8:48 pm
DailyHourly
Daily ForecastHourly Forecast
Today 10:00 pm
weather icon
18° | 20°°C 0 mm 0% 7 mph 57 % 1021 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
9° | 16°°C 0 mm 0% 9 mph 83 % 1022 mb 0 mm/h
Mon May 19 10:00 pm
weather icon
11° | 19°°C 0.2 mm 20% 13 mph 78 % 1022 mb 0 mm/h
Tue May 20 10:00 pm
weather icon
9° | 21°°C 0.35 mm 35% 9 mph 81 % 1022 mb 0 mm/h
Wed May 21 10:00 pm
weather icon
11° | 20°°C 0.09 mm 9% 11 mph 79 % 1020 mb 0 mm/h
Today 10:00 pm
weather icon
15° | 17°°C 0 mm 0% 7 mph 57 % 1021 mb 0 mm/h
Tomorrow 1:00 am
weather icon
12° | 14°°C 0 mm 0% 5 mph 68 % 1022 mb 0 mm/h
Tomorrow 4:00 am
weather icon
11° | 11°°C 0 mm 0% 6 mph 83 % 1021 mb 0 mm/h
Tomorrow 7:00 am
weather icon
9° | 9°°C 0 mm 0% 8 mph 82 % 1021 mb 0 mm/h
Tomorrow 10:00 am
weather icon
11° | 11°°C 0 mm 0% 6 mph 69 % 1022 mb 0 mm/h
Tomorrow 1:00 pm
weather icon
15° | 15°°C 0 mm 0% 7 mph 52 % 1021 mb 0 mm/h
Tomorrow 4:00 pm
weather icon
16° | 16°°C 0 mm 0% 9 mph 49 % 1020 mb 0 mm/h
Tomorrow 7:00 pm
weather icon
14° | 14°°C 0 mm 0% 8 mph 56 % 1019 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€92,469.39
-0.76%
Ethereum(ETH)
€2,216.49
-4.21%
Tether(USDT)
€0.90
0.00%
XRP(XRP)
€2.09
-3.16%
Solana(SOL)
€148.92
-2.69%
USDC(USDC)
€0.90
0.00%
Dogecoin(DOGE)
€0.192512
-5.18%
Shiba Inu(SHIB)
€0.000013
-5.14%
Pepe(PEPE)
€0.000011
-8.19%
Peanut the Squirrel(PNUT)
€0.269711
-10.27%
Scroll to Top