CVE-2023-30631


Apache Traffic Server: Configuration option to block the PUSH method in ATS didn't work

Improper Input Validation vulnerability in Apache Software Foundation Apache Traffic Server.  The configuration option proxy.config.http.push_method_enabled didn't function.  However, by default the PUSH method is blocked in the ip_allow configuration file.This issue affects Apache Traffic Server: from 8.0.0 through 9.2.0. 8.x users should upgrade to 8.1.7 or later versions 9.x users should upgrade to 9.2.1 or later versions



We have discovered 598 live websites that are affected by CVE-2023-30631.

Contact us to get more info




Affected Software

Product  ATS
Category Web Servers
Vulnerable Versions
  • from 8 through 9.2
Total Vulnerable Versions41
Vulnerable Domains598 live websites (35.57% of ATS install base)


Common Weakness Enumeration


CWE-20 Improper Input Validation


Distribution by Website Rank

The diagram provides a graphic representation of the correlation between the occurrence of CVE-2023-30631 and the relative popularity of websites


Details

  • Published - Jun 14, 2023
  • Updated - Jun 14, 2023

Credits

  • Chris Lemmons (finder)





Countries

United States289 websites



Germany200 websites
Italy31 websites
GB18 websites
France15 websites
Finland11 websites
Russia10 websites
Netherlands7 websites
Japan4 websites
Belgium3 websites

TLDs

.org278 websites
.info91 websites
.com53 websites
.it21 websites
.de19 websites
.ru10 websites
.fi9 websites
.net4 websites
.nl3 websites
.edu2 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


Geographical Distribution

The distribution of websites across the globe that are exposed to CVE-2023-30631 through included software libraries and plugins.



References


Websites affected by CVE-2023-30631

Top websites that are affected by CVE-2023-30631. Please click on the "Contact us" button above to get more information.
DomainCountryRankContacts
**.*********.org United States**
*******.*********.org United States***
***.*********.org United States*,***
**.*********.org United States*,***
**.*********.org United States*,***
**.*.*********.org United States*,***
****.*********.org United States*,***
**.*********.org United States*,***
**.*********.org United States*,***
**.*********.org United States*,***
See full domain list