CVE-2024-56195

Apache Traffic Server: Intercept plugins are not access controlled

Improper Access Control vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.2.0 through 9.2.8, from 10.0.0 through 10.0.3. Users are recommended to upgrade to version 9.2.9 or 10.0.4, which fixes the issue.


We have discovered 1,295 live websites that are affected by CVE-2024-56195.

Test my site




Affected Software

Product  ATS
Category Web Servers
Vulnerable Domains1,295 live websites (60.57% of ATS install base)
Vulnerable Versions
  • from 9.2 through 9.2.8
  • from 10 through 10.0.3
Vulnerable Versions Count11 versions ( 28.21% of all versions)


Common Weakness Enumeration

CWE-284 Improper Access Control



Details

  • Published - Mar 6, 2025
  • Updated - Mar 6, 2025

Credits

  • Masaori Koshiba (reporter)

CVE-2024-56195 usage by Country

United States1,046 websites



Germany153 websites
GB38 websites
Italy26 websites
Isle of Man7 websites
China3 websites
France3 websites
Canada2 websites
India2 websites
Netherlands2 websites

CVE-2024-56195 usage by TLD

.org882 websites
.com139 websites
.net55 websites
.it38 websites
.de24 websites
.org.uk11 websites
.edu10 websites
.co.uk3 websites
.ca2 websites
.com.br2 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-56195

Top websites that are affected by CVE-2024-56195. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
**.*********.org United States**
*******.com United States**
**.*********.org United States***
*******.*********.org United States***
**.*********.org United States***
*********.org United States*,***
*********.org United States*,***
**.*********.org United States*,***
**.*********.org United States*,***
************.net United States*,***
See full domain list

FAQ

CVE-2024-56195 is Improper Access Control in ATS
A total of 1,295 websites have been identified as vulnerable to CVE-2024-56195, discovered through global website indexing conducted by WebTechSurvey.
ATS is susceptible to CVE-2024-56195 vulnerability.
ATS versions before, and including, 10.0.3 are vulnerable to CVE-2024-56195.