An issue was discovered in Squid through 4.7. When handling requests from users, Squid checks its rules to see if the request should be denied. Squid by default comes with rules to block access to the Cache Manager, which serves detailed server information meant for the maintainer. This rule is implemented via url_regex. The handler for url_regex rules URL decodes an incoming request. This allows an attacker to encode their URL to bypass the url_regex check, and gain access to the blocked resource.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade libecapUpgrade libecap-devel | May 4, 2022 | Apr 15, 2020 |
| Amazon Linux Ami 2 | — | Upgrade squid-migration-scriptUpgrade squid-sysvinitUpgrade squid-debuginfoUpgrade squid | Sep 28, 2023 | Apr 15, 2020 |
| Centos_linux | — | Upgrade squid-debugsourceUpgrade libecapUpgrade squid-debuginfoUpgrade libecap-debuginfoUpgrade libecap-debugsourceUpgrade libecap-develUpgrade squid | Nov 5, 2020 | Apr 15, 2020 |
| Debian | — | Upgrade squid | May 11, 2020 | Apr 15, 2020 |
| Huawei Euleros 2_0_sp8 | — | Upgrade squid | Aug 31, 2020 | Apr 15, 2020 |
| Oracle_linux | — | Upgrade libecapUpgrade squidUpgrade libecap-devel | Oct 1, 2022 | Apr 24, 2020 |
| Redhat_linux | — | Upgrade squidUpgrade libecap-debugsourceUpgrade squid-debuginfoUpgrade libecapUpgrade libecap-debuginfoUpgrade libecap-develUpgrade squid-debugsourceNo solution exists | Nov 5, 2020 | Apr 15, 2020 |
| Rocky_linux | — | Upgrade libecap-develUpgrade libecap-debuginfoUpgrade libecapUpgrade libecap-debugsource | Mar 12, 2024 | Apr 15, 2020 |
| Suse | — | Upgrade squidUpgrade squid3 | May 9, 2020 | Apr 15, 2020 |
| Ubuntu | — | Upgrade squid | Aug 5, 2020 | Apr 15, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub