Incorrect processing of responses to If-None-Modified HTTP conditional requests in Squid HTTP Proxy 3.1.10 through 3.1.23, 3.2.0.3 through 3.5.22, and 4.0.1 through 4.0.16 leads to client-specific Cookie data being leaked to other clients. Attack requests can easily be crafted by a client to probe a cache for this information.
CVSS Details
- CVSS 3.0 Base Score: 7.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade squid | Sep 20, 2017 | Jan 27, 2017 |
| Centos_linux | — | Upgrade squid-sysvinitUpgrade squid34-debuginfoUpgrade squidUpgrade squid34Upgrade squid-debuginfoUpgrade squid-migration-script | Jan 27, 2017 | Dec 16, 2016 |
| Debian | — | Upgrade squid3 | Dec 25, 2016 | Dec 16, 2016 |
| Freebsd | — | Upgrade squidUpgrade squid-devel | Dec 23, 2016 | Dec 23, 2016 |
| Huawei Euleros 2_0_sp1 | — | Upgrade squidUpgrade squid-migration-script | Nov 30, 2017 | Jan 27, 2017 |
| Huawei Euleros 2_0_sp2 | — | Upgrade squid-migration-scriptUpgrade squid | Nov 30, 2017 | Jan 27, 2017 |
| Oracle Solaris | — | Upgrade web/proxy/squid to version 3.5.23-0.175.3.17.0.1.0 on Solaris 11.3 | May 29, 2017 | Jan 27, 2017 |
| Oracle_linux | — | Upgrade squid-migration-scriptUpgrade squid-sysvinitUpgrade squidUpgrade squid34 | Jan 24, 2017 | Dec 16, 2016 |
| Redhat_linux | — | Upgrade squidUpgrade squid34Upgrade squid34-debuginfoNo solution existsUpgrade squid-migration-scriptUpgrade squid-debuginfoUpgrade squid-sysvinit | Feb 3, 2017 | Dec 16, 2016 |
| Suse | — | Upgrade squidUpgrade squid3 | Jan 12, 2017 | Dec 16, 2016 |
| Ubuntu | — | Upgrade squid3 | Feb 7, 2017 | Dec 16, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub