{"id":"CVE-2014-3624","details":"Apache Traffic Server 5.1.x before 5.1.1 allows remote attackers to bypass access restrictions by leveraging failure to properly tunnel remap requests using CONNECT.","modified":"2026-04-10T03:44:40.672055Z","published":"2017-10-30T14:29:00Z","references":[{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/101630"},{"type":"ADVISORY","url":"https://issues.apache.org/jira/browse/TS-2677"},{"type":"FIX","url":"https://issues.apache.org/jira/browse/TS-2677"},{"type":"REPORT","url":"https://issues.apache.org/jira/browse/TS-2677"},{"type":"WEB","url":"http://mail-archives.apache.org/mod_mbox/www-announce/201411.mbox/%3C20141101231749.2E3561043F%40minotaur.apache.org%3E"}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}