Improper Authentication vulnerability in TLS origin validation of Apache Traffic Server allows an attacker to create a man in the middle attack. This issue affects Apache Traffic Server 8.0.0 to 8.1.0.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Link | Tags |
---|---|
https://lists.apache.org/thread/zblwzcfs9ryhwjr89wz4osw55pxm6dx6 | vendor advisory mailing list |
https://www.debian.org/security/2022/dsa-5153 | third party advisory vendor advisory |