An issue was discovered in Squid through 4.7. When handling requests from users, Squid checks its rules to see if the request should be denied. Squid by default comes with rules to block access to the Cache Manager, which serves detailed server information meant for the maintainer. This rule is implemented via url_regex. The handler for url_regex rules URL decodes an incoming request. This allows an attacker to encode their URL to bypass the url_regex check, and gain access to the blocked resource.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade libecap-develUpgrade libecap | May 4, 2022 | Apr 15, 2020 |
| Amazon Linux Ami 2 | — | Upgrade squidUpgrade squid-migration-scriptUpgrade squid-sysvinitUpgrade squid-debuginfo | Sep 28, 2023 | Apr 15, 2020 |
| Centos_linux | — | Upgrade libecap-debugsourceUpgrade libecap-debuginfoUpgrade libecapUpgrade squid-debuginfoUpgrade squid-debugsourceUpgrade libecap-develUpgrade squid | Nov 5, 2020 | Apr 15, 2020 |
| Debian | — | Upgrade squid | May 11, 2020 | Apr 15, 2020 |
| Huawei Euleros 2_0_sp8 | — | Upgrade squid | Aug 31, 2020 | Apr 15, 2020 |
| Oracle_linux | — | Upgrade squidUpgrade libecapUpgrade libecap-devel | Oct 1, 2022 | Apr 24, 2020 |
| Redhat_linux | — | Upgrade squid-debugsourceNo solution existsUpgrade libecap-debugsourceUpgrade libecap-debuginfoUpgrade squidUpgrade libecap-develUpgrade squid-debuginfoUpgrade libecap | Nov 5, 2020 | Apr 15, 2020 |
| Rocky_linux | — | Upgrade libecapUpgrade libecap-debuginfoUpgrade libecap-debugsourceUpgrade libecap-devel | Mar 12, 2024 | Apr 15, 2020 |
| Suse | — | Upgrade squidUpgrade squid3 | May 9, 2020 | Apr 15, 2020 |
| Ubuntu | — | Upgrade squid | Aug 5, 2020 | Apr 15, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub