Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-46846

Опубликовано: 03 нояб. 2023
Источник: debian
EPSS Низкий

Описание

SQUID is vulnerable to HTTP request smuggling, caused by chunked decoder lenience, allows a remote attacker to perform Request/Response smuggling past firewall and frontend security systems.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
squidfixed6.5-1package
squid3removedpackage

Примечания

  • https://github.com/squid-cache/squid/security/advisories/GHSA-j83v-w3p4-5cqh

EPSS

Процентиль: 92%
0.08411
Низкий

Связанные уязвимости

CVSS3: 9.3
ubuntu
больше 1 года назад

SQUID is vulnerable to HTTP request smuggling, caused by chunked decoder lenience, allows a remote attacker to perform Request/Response smuggling past firewall and frontend security systems.

CVSS3: 9.3
redhat
больше 1 года назад

SQUID is vulnerable to HTTP request smuggling, caused by chunked decoder lenience, allows a remote attacker to perform Request/Response smuggling past firewall and frontend security systems.

CVSS3: 9.3
nvd
больше 1 года назад

SQUID is vulnerable to HTTP request smuggling, caused by chunked decoder lenience, allows a remote attacker to perform Request/Response smuggling past firewall and frontend security systems.

oracle-oval
4 месяца назад

ELSA-2024-11049: squid security update (IMPORTANT)

CVSS3: 5.3
fstec
больше 1 года назад

Уязвимость декодера chunked прокси-сервера Squid, позволяющая нарушителю взаимодействовать с сервером напрямую

EPSS

Процентиль: 92%
0.08411
Низкий