CVE-2024-50306

Name
CVE-2024-50306
Description
Unchecked return value can allow Apache Traffic Server to retain privileges on startup. This issue affects Apache Traffic Server: from 9.2.0 through 9.2.5, from 10.0.0 through 10.0.1. Users are recommended to upgrade to version 9.2.6 or 10.0.2, which fixes the issue.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
vendor-advisory https://lists.apache.org/thread/y15fh6c7kyqvzm0f9odw7c5jh4r4np0y
af854a3a-2127-422b-91ae-364da2661108 https://lists.debian.org/debian-lts-announce/2025/02/msg00018.html

Match rules

CPE URI Source package Min version Max version
apache-traffic-server >= 9.2.0 <= 9.2.5
apache-traffic-server >= 10.0.0 <= 10.0.1
cpe:2.3:a:apache_software_foundation:apache_traffic_server:*:*:*:*:*:*:*:* apache-traffic-server >= 9.2.0 <= 9.2.5
cpe:2.3:a:apache_software_foundation:apache_traffic_server:*:*:*:*:*:*:*:* apache-traffic-server >= 10.0.0 <= 10.0.1
cpe:2.3:a:apache:traffic_server:*:-:*:*:*:*:*:* traffic_server >= 9.0.0 < 9.2.6
cpe:2.3:a:apache:traffic_server:*:*:*:*:*:*:*:* traffic_server >= 10.0.0 < 10.0.2

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
trafficserver9 edge-community 9.2.6-r0 Peter Shkenev <santurysim@gmail.com> fixed
trafficserver9 3.22-community 9.2.6-r0 None fixed
trafficserver9 3.21-community 9.2.6-r0 Peter Shkenev <santurysim@gmail.com> fixed