CVE-2022-40743


Apache Traffic Server: Security issues with the xdebug plugin

Improper Input Validation vulnerability for the xdebug plugin in Apache Software Foundation Apache Traffic Server can lead to cross site scripting and cache poisoning attacks.This issue affects Apache Traffic Server: 9.0.0 to 9.1.3. Users should upgrade to 9.1.4 or later versions.



We have discovered 219 live websites that are affected by CVE-2022-40743.

Contact us to get more info




Affected Software

Product  ATS
Category Web Servers
Vulnerable Versions
  • from 9 through 9.1.3
Total Vulnerable Versions41
Vulnerable Domains219 live websites (13.03% of ATS install base)


Common Weakness Enumeration


CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')


Distribution by Website Rank

The diagram provides a graphic representation of the correlation between the occurrence of CVE-2022-40743 and the relative popularity of websites


Details

  • Published - Dec 19, 2022
  • Updated - Jul 17, 2023

Credits

  • Nick Frost (finder)





Countries

United States10 websites



Germany189 websites
GB14 websites
Japan2 websites
Finland1 websites
Hong Kong1 websites
Italy1 websites
Netherlands1 websites

TLDs

.info91 websites
.de16 websites
.com11 websites
.net4 websites
.co.jp1 websites
.eu1 websites
.fi1 websites
.nl1 websites
.org1 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


Geographical Distribution

The distribution of websites across the globe that are exposed to CVE-2022-40743 through included software libraries and plugins.



References


Websites affected by CVE-2022-40743

Top websites that are affected by CVE-2022-40743. Please click on the "Contact us" button above to get more information.
DomainCountryRankContacts
*****.****.******.community GB***,***
*****.****.******.community GB***,***
*****.****.******.community GB***,***
****.******.community GB***,***
***********.****.*********.info Germany***,***
***********.****.******.community GB*,***,***
*******************************.de Germany*,***,***
***.*******************************.de Germany*,***,***
****.*********.info Germany*,***,***
******************************.de Germany*,***,***
See full domain list