Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.8, from 10.0.0 through 10.0.3. Users are recommended to upgrade to version 9.2.9 or 10.0.4, which fixes the issue.
We have discovered 400 live websites that are affected by CVE-2024-38311.
| Product | |
| Category | Web Servers |
| Vulnerable Domains | 400 live websites (36% of ATS install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 13 versions ( 48% of all versions) |
| 49 websites | |
| 132 websites | |
| 131 websites | |
| 35 websites | |
| 10 websites | |
| 8 websites | |
| 7 websites | |
| 7 websites | |
| 6 websites | |
| 5 websites |
| .com.cn | 93 websites |
| .com | 82 websites |
| .org | 26 websites |
| .cn | 22 websites |
| .de | 13 websites |
| .ru | 11 websites |
| .org.uk | 11 websites |
| .it | 10 websites |
| .fi | 8 websites |
| .net | 6 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ********.************.net | **,*** | ||
| ****.******.jp | **,*** | ||
| ********.******.com | **,*** | ||
| ************.******.com | **,*** | ||
| ***.**********.de | **,*** | ||
| *********.******.com | **,*** | ||
| *********.******.***.cn | **,*** | ||
| ******.**********.de | ***,*** | ||
| ******.***.cn | ***,*** | ||
| *****.******.***.cn | ***,*** |
FAQ