CVE-2024-56196

Apache Traffic Server: ACL is not fully compatible with older versions

Improper Access Control vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 10.0.0 through 10.0.3. Users are recommended to upgrade to version 10.0.4, which fixes the issue.


We have discovered 64 live websites that are affected by CVE-2024-56196.

Test my site




Affected Software

Product  ATS
Category Web Servers
Vulnerable Domains64 live websites (2.99% of ATS install base)
Vulnerable Versions
  • from 10 through 10.0.3
Vulnerable Versions Count3 versions ( 7.69% of all versions)


Common Weakness Enumeration

CWE-284 Improper Access Control



Details

  • Published - Mar 6, 2025
  • Updated - Mar 6, 2025

Credits

  • Chris McFarlen (reporter)

CVE-2024-56196 usage by Country

United States44 websites



Isle of Man7 websites
China3 websites
Brazil1 websites
Chile1 websites
Germany1 websites
France1 websites
GB1 websites
Netherlands1 websites

CVE-2024-56196 usage by TLD

.net43 websites
.com16 websites
.org2 websites
.com.br1 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-56196

Top websites that are affected by CVE-2024-56196. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
****.*************.******.org United States***,***
********.com Isle of Man***,***
**.*************.******.org United States*,***,***
***.********.com Turkey*,***,***
*******************.****.*****.**************.net Singapore*,***,***
****.********.online Germany*,***,***
*********.****.*****.**************.net United States*,***,***
*************.****.*****.**************.net United States*,***,***
*******************.****.*****.**************.net United States*,***,***
***************.****.*****.**************.net United States*,***,***
See full domain list

FAQ

CVE-2024-56196 is Improper Access Control in ATS
A total of 64 websites have been identified as vulnerable to CVE-2024-56196, discovered through global website indexing conducted by WebTechSurvey.
ATS is susceptible to CVE-2024-56196 vulnerability.
ATS versions before, and including, 10.0.3 are vulnerable to CVE-2024-56196.