Incorrect processing of responses to If-None-Modified HTTP conditional requests in Squid HTTP Proxy 3.1.10 through 3.1.23, 3.2.0.3 through 3.5.22, and 4.0.1 through 4.0.16 leads to client-specific Cookie data being leaked to other clients. Attack requests can easily be crafted by a client to probe a cache for this information.
CVSS Details
- CVSS 3.0 Base Score: 7.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade squid | Sep 20, 2017 | Jan 27, 2017 |
| Centos_linux | — | Upgrade squid34-debuginfoUpgrade squid-sysvinitUpgrade squid-debuginfoUpgrade squidUpgrade squid-migration-scriptUpgrade squid34 | Jan 27, 2017 | Dec 16, 2016 |
| Debian | — | Upgrade squid3 | Dec 25, 2016 | Dec 16, 2016 |
| Freebsd | — | Upgrade squidUpgrade squid-devel | Dec 23, 2016 | Dec 23, 2016 |
| Huawei Euleros 2_0_sp1 | — | Upgrade squidUpgrade squid-migration-script | Nov 30, 2017 | Jan 27, 2017 |
| Huawei Euleros 2_0_sp2 | — | Upgrade squidUpgrade squid-migration-script | Nov 30, 2017 | Jan 27, 2017 |
| Oracle Solaris | — | Upgrade web/proxy/squid to version 3.5.23-0.175.3.17.0.1.0 on Solaris 11.3 | May 29, 2017 | Jan 27, 2017 |
| Oracle_linux | — | Upgrade squid34Upgrade squidUpgrade squid-sysvinitUpgrade squid-migration-script | Jan 24, 2017 | Dec 16, 2016 |
| Redhat_linux | — | Upgrade squidUpgrade squid34Upgrade squid-migration-scriptUpgrade squid-sysvinitUpgrade squid-debuginfoUpgrade squid34-debuginfoNo solution exists | Feb 3, 2017 | Dec 16, 2016 |
| Suse | — | Upgrade squid3Upgrade squid | Jan 12, 2017 | Dec 16, 2016 |
| Ubuntu | — | Upgrade squid3 | Feb 7, 2017 | Dec 16, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub