CVE-2023-41752


Apache Traffic Server: s3_auth plugin problem with hash calculation

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Traffic Server.This issue affects Apache Traffic Server: from 8.0.0 through 8.1.8, from 9.0.0 through 9.2.2. Users are recommended to upgrade to version 8.1.9 or 9.2.3, which fixes the issue.



We have discovered 651 live websites that are affected by CVE-2023-41752.

Contact us to get more info




Affected Software

Product  ATS
Category Web Servers
Vulnerable Versions
  • from 8 through 8.1.8
  • from 9 through 9.2.2
Total Vulnerable Versions41
Vulnerable Domains651 live websites (38.73% of ATS install base)


Common Weakness Enumeration


CWE-200 Exposure of Sensitive Information to an Unauthorized Actor


Distribution by Website Rank

The diagram provides a graphic representation of the correlation between the occurrence of CVE-2023-41752 and the relative popularity of websites


Details

  • Published - Oct 17, 2023
  • Updated - Oct 17, 2023

Credits

  • Masakazu Kitajo (finder)





Countries

United States289 websites



Germany200 websites
Italy58 websites
GB50 websites
Finland11 websites
France11 websites
Russia10 websites
Netherlands7 websites
Japan4 websites
Belgium3 websites

TLDs

.org292 websites
.info91 websites
.com60 websites
.it43 websites
.de17 websites
.org.uk12 websites
.ru10 websites
.fi9 websites
.net6 websites
.nl3 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


Geographical Distribution

The distribution of websites across the globe that are exposed to CVE-2023-41752 through included software libraries and plugins.



References


Websites affected by CVE-2023-41752

Top websites that are affected by CVE-2023-41752. Please click on the "Contact us" button above to get more information.
DomainCountryRankContacts
**.*********.org United States**
*******.*********.org United States***
***.*********.org United States*,***
**.*********.org United States*,***
**.*********.org United States*,***
**.*.*********.org United States*,***
****.*********.org United States*,***
**.*********.org United States*,***
**.*********.org United States*,***
**.*********.org United States*,***
See full domain list