Description
Invalid Accept-Encoding header can cause Apache Traffic Server to fail cache lookup and force forwarding requests. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.10, from 9.0.0 through 9.2.4. Users are recommended to upgrade to version 8.1.11 or 9.2.5, which fixes the issue.
Remediation
References
Related Vulnerabilities
Apache HTTP Server Server-Side Request Forgery (SSRF) Vulnerability (CVE-2021-40438)
WordPress Plugin MStore API-Create Native Android & iOS Apps On The Cloud Security Bypass (3.9.2)
Joomla! Core 1.5.x Security Bypass (1.5.0 - 1.5.13)
WordPress Plugin LearnPress-WordPress LMS Security Bypass (4.1.4.1)
Moodle Permissions, Privileges, and Access Controls Vulnerability (CVE-2014-0124)