CVE-2023-33934


Apache Traffic Server: Differential fuzzing for HTTP request parsing discrepancies

Improper Input Validation vulnerability in Apache Software Foundation Apache Traffic Server.This issue affects Apache Traffic Server: through 9.2.1.



We have discovered 1,404 live websites that are affected by CVE-2023-33934.

Contact us to get more info




Affected Software

Product  ATS
Category Web Servers
Vulnerable Versions
  • from 0 through 9.2.1
Total Vulnerable Versions41
Vulnerable Domains1,404 live websites (83.52% of ATS install base)


Common Weakness Enumeration


CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')


Distribution by Website Rank

The diagram provides a graphic representation of the correlation between the occurrence of CVE-2023-33934 and the relative popularity of websites


Details

  • Published - Aug 9, 2023
  • Updated - Sep 28, 2023

Credits

  • Bahruz Jabiyev, Anthony Gavazzi, Engin Kirda, Kaan Onarlioglu, Adi Peleg, Harvey Tuch (finder)





Countries

United States407 websites



China488 websites
Germany218 websites
Switzerland66 websites
Italy57 websites
France32 websites
GB27 websites
Romania23 websites
Finland12 websites
Netherlands11 websites

TLDs

.com.cn405 websites
.org298 websites
.com207 websites
.info93 websites
.cn60 websites
.ch54 websites
.it39 websites
.de31 websites
.net26 websites
.fi10 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


Geographical Distribution

The distribution of websites across the globe that are exposed to CVE-2023-33934 through included software libraries and plugins.



References


Websites affected by CVE-2023-33934

Top websites that are affected by CVE-2023-33934. Please click on the "Contact us" button above to get more information.
DomainCountryRankContacts
**.*********.org United States**
*******.*********.org United States***
*.*******.cn China*,***
***.*********.org United States*,***
**.*********.org United States*,***
****.***.cn China*,***
***.****.***.cn China*,***
**.*********.org United States*,***
**.*.*********.org United States*,***
****.*********.org United States*,***
See full domain list