Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mm65-p7g9-c5hr

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.1

Описание

An issue was discovered in Squid 3.x and 4.x through 4.8 when the append_domain setting is used (because the appended characters do not properly interact with hostname length restrictions). Due to incorrect message processing, it can inappropriately redirect traffic to origins it should not be delivered to.

An issue was discovered in Squid 3.x and 4.x through 4.8 when the append_domain setting is used (because the appended characters do not properly interact with hostname length restrictions). Due to incorrect message processing, it can inappropriately redirect traffic to origins it should not be delivered to.

EPSS

Процентиль: 89%
0.04678
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-352

Связанные уязвимости

CVSS3: 6.1
ubuntu
больше 5 лет назад

An issue was discovered in Squid 3.x and 4.x through 4.8 when the append_domain setting is used (because the appended characters do not properly interact with hostname length restrictions). Due to incorrect message processing, it can inappropriately redirect traffic to origins it should not be delivered to.

CVSS3: 7.4
redhat
больше 5 лет назад

An issue was discovered in Squid 3.x and 4.x through 4.8 when the append_domain setting is used (because the appended characters do not properly interact with hostname length restrictions). Due to incorrect message processing, it can inappropriately redirect traffic to origins it should not be delivered to.

CVSS3: 6.1
nvd
больше 5 лет назад

An issue was discovered in Squid 3.x and 4.x through 4.8 when the append_domain setting is used (because the appended characters do not properly interact with hostname length restrictions). Due to incorrect message processing, it can inappropriately redirect traffic to origins it should not be delivered to.

CVSS3: 6.1
debian
больше 5 лет назад

An issue was discovered in Squid 3.x and 4.x through 4.8 when the appe ...

CVSS3: 6.1
fstec
больше 5 лет назад

Уязвимость параметра append_domain прокси-сервера Squid, связанная с подделкой межсайтовых запросов, позволяющая нарушителю получить доступ к конфиденциальным данным и нарушить их целостность

EPSS

Процентиль: 89%
0.04678
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-352