An issue was discovered in Squid 4.9 through 4.17 and 5.0.6 through 5.6. Due to inconsistent handling of internal URIs, there can be Exposure of Sensitive Information about clients using the proxy via an HTTPS request to an internal cache manager URL. This is fixed in 5.7.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade squid | Mar 26, 2024 | Dec 25, 2022 |
| Amazon Linux Ami 2 | — | Upgrade squidUpgrade squid-sysvinitUpgrade squid-migration-scriptUpgrade squid-debuginfo | Feb 23, 2023 | Dec 25, 2022 |
| Amazon_linux | — | Upgrade squid | Feb 23, 2023 | Sep 26, 2022 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Dec 25, 2022 |
| Debian | — | Upgrade squid | Oct 14, 2022 | Oct 14, 2022 |
| Freebsd | — | Upgrade squid | Nov 4, 2022 | Sep 26, 2022 |
| Huawei Euleros 2_0_sp8 | — | Upgrade squid | Dec 9, 2022 | Dec 8, 2022 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Dec 25, 2022 |
| Suse | — | Upgrade squid | Oct 26, 2022 | Sep 23, 2022 |
| Ubuntu | — | Upgrade squid | Sep 27, 2022 | Sep 26, 2022 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Dec 25, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub