SQL injection in Apache Traffic Control
High severity
GitHub Reviewed
Published
Dec 23, 2024
to the GitHub Advisory Database
•
Updated Feb 11, 2025
Package
Affected versions
>= 8.0.0, < 8.0.2
Patched versions
8.0.2
Description
Published by the National Vulnerability Database
Dec 23, 2024
Published to the GitHub Advisory Database
Dec 23, 2024
Reviewed
Dec 23, 2024
Last updated
Feb 11, 2025
An SQL injection vulnerability in Traffic Ops in Apache Traffic Control <= 8.0.1, >= 8.0.0 allows a privileged user with role "admin", "federation", "operations", "portal", or "steering" to execute arbitrary SQL against the database by sending a specially-crafted PUT request.
Users are recommended to upgrade to version Apache Traffic Control 8.0.2 if you run an affected version of Traffic Ops.
References