GHSA-pw59-4qgf-jxr8 · Severity: medium · Ecosystem: go — Cache Manipulation Attack in Apache Traffic Control
When ORT (now via atstccfg) generates ip_allow.config files in Apache Traffic Control 3.0.0 to 3.1.0 and 4.0.0 to 4.1.0, those files include permissions that allow bad actors to push arbitrary content into and remove arbitrary content from CDN cache servers. Additionally, these permissions are potentially extended to IP addresses outside the desired range, resulting in them being granted to clients possibly outside the CDN arcitechture.
Conclusion & alert: CVE-2020-17522 is rated Moderate Risk (56.1/100): CVSS Medium severity, with medium exploitation likelihood (EPSS 3.93%). Core evidence: EPSS rose +1.77% over the last day, indicating growing attacker interest. Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 2.16% | 3.93% | +1.77% |
| 2 | 2025-07-27 | 2.88% | 2.16% | -0.71% |
| 3 | 2025-04-14 | — | 2.88% | — |
Full EPSS history (21 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 5.8 | 3.1 | MEDIUM |
|
3.9 | 1.4 | [email protected] |
| 5.0 | 2.0 | MEDIUM |
|
10.0 | 2.9 | [email protected] |
GHSA-pw59-4qgf-jxr8 · Severity: medium · Ecosystem: go — Cache Manipulation Attack in Apache Traffic Control
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| apache | traffic_control | >= 3.0.0, <= 3.1.0 | cpe:2.3:a:apache:traffic_control:*:*:*:*:*:*:*:* |
| apache | traffic_control | >= 4.0.0, <= 4.1.0 | cpe:2.3:a:apache:traffic_control:*:*:*:*:*:*:*:* |