CVE-2024-45387 is an SQL injection vulnerability affecting Apache Traffic Control versions 8.0.0 through 8.0.1. This flaw allows a privileged user with specific roles (admin, federation, operations, portal, or steering) to execute arbitrary SQL commands against the database by sending a specially crafted PUT request. With a CVSS score of 8.8 (HIGH), this vulnerability is remotely exploitable with low attack complexity, potentially leading to high impact on confidentiality, integrity, and availability. While there is no evidence of active exploitation or public exploit code, its high EPSS score and community discussion indicate significant concern, and users are urged to upgrade to Apache Traffic Control 8.0.2.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 8.0.0, < 8.0.2CPE matchmatch criteria | cpe:2.3:a:apache:traffic_control:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.