Incorrect processing of responses to If-None-Modified HTTP conditional requests in Squid HTTP Proxy 3.1.10 through 3.1.23, 3.2.0.3 through 3.5.22, and 4.0.1 through 4.0.16 leads to client-specific Cookie data being leaked to other clients. Attack requests can easily be crafted by a client to probe a cache for this information.
CVSS Details
- CVSS 3.0 Base Score: 7.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade squid | Sep 20, 2017 | Jan 27, 2017 |
| Centos_linux | — | Upgrade squid34-debuginfoUpgrade squid-sysvinitUpgrade squid-debuginfoUpgrade squid34Upgrade squid-migration-scriptUpgrade squid | Jan 27, 2017 | Dec 16, 2016 |
| Debian | — | Upgrade squid3 | Dec 25, 2016 | Dec 16, 2016 |
| Freebsd | — | Upgrade squid-develUpgrade squid | Dec 23, 2016 | Dec 23, 2016 |
| Huawei Euleros 2_0_sp1 | — | Upgrade squidUpgrade squid-migration-script | Nov 30, 2017 | Jan 27, 2017 |
| Huawei Euleros 2_0_sp2 | — | Upgrade squidUpgrade squid-migration-script | Nov 30, 2017 | Jan 27, 2017 |
| Oracle Solaris | — | Upgrade web/proxy/squid to version 3.5.23-0.175.3.17.0.1.0 on Solaris 11.3 | May 29, 2017 | Jan 27, 2017 |
| Oracle_linux | — | Upgrade squid-migration-scriptUpgrade squid-sysvinitUpgrade squid34Upgrade squid | Jan 24, 2017 | Dec 16, 2016 |
| Redhat_linux | — | Upgrade squidUpgrade squid34Upgrade squid-migration-scriptUpgrade squid34-debuginfoUpgrade squid-debuginfoNo solution existsUpgrade squid-sysvinit | Feb 3, 2017 | Dec 16, 2016 |
| Suse | — | Upgrade squidUpgrade squid3 | Jan 12, 2017 | Dec 16, 2016 |
| Ubuntu | — | Upgrade squid3 | Feb 7, 2017 | Dec 16, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub