Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3vc4-p4vg-f376

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Squid 2.5, when processing the configuration file, parses empty Access Control Lists (ACLs), including proxy_auth ACLs without defined auth schemes, in a way that effectively removes arguments, which could allow remote attackers to bypass intended ACLs if the administrator ignores the parser warnings.

Squid 2.5, when processing the configuration file, parses empty Access Control Lists (ACLs), including proxy_auth ACLs without defined auth schemes, in a way that effectively removes arguments, which could allow remote attackers to bypass intended ACLs if the administrator ignores the parser warnings.

EPSS

Процентиль: 76%
0.01009
Низкий

Связанные уязвимости

ubuntu
больше 20 лет назад

Squid 2.5, when processing the configuration file, parses empty Access Control Lists (ACLs), including proxy_auth ACLs without defined auth schemes, in a way that effectively removes arguments, which could allow remote attackers to bypass intended ACLs if the administrator ignores the parser warnings.

nvd
больше 20 лет назад

Squid 2.5, when processing the configuration file, parses empty Access Control Lists (ACLs), including proxy_auth ACLs without defined auth schemes, in a way that effectively removes arguments, which could allow remote attackers to bypass intended ACLs if the administrator ignores the parser warnings.

debian
больше 20 лет назад

Squid 2.5, when processing the configuration file, parses empty Access ...

EPSS

Процентиль: 76%
0.01009
Низкий