Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-p6vj-j24g-56wp

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.6

Описание

client_side.cc in Squid before 3.5.18 and 4.x before 4.0.10 does not properly ignore the Host header when absolute-URI is provided, which allows remote attackers to conduct cache-poisoning attacks via an HTTP request.

client_side.cc in Squid before 3.5.18 and 4.x before 4.0.10 does not properly ignore the Host header when absolute-URI is provided, which allows remote attackers to conduct cache-poisoning attacks via an HTTP request.

EPSS

Процентиль: 97%
0.39528
Средний

8.6 High

CVSS3

Дефекты

CWE-345

Связанные уязвимости

CVSS3: 8.6
ubuntu
больше 9 лет назад

client_side.cc in Squid before 3.5.18 and 4.x before 4.0.10 does not properly ignore the Host header when absolute-URI is provided, which allows remote attackers to conduct cache-poisoning attacks via an HTTP request.

redhat
больше 9 лет назад

client_side.cc in Squid before 3.5.18 and 4.x before 4.0.10 does not properly ignore the Host header when absolute-URI is provided, which allows remote attackers to conduct cache-poisoning attacks via an HTTP request.

CVSS3: 8.6
nvd
больше 9 лет назад

client_side.cc in Squid before 3.5.18 and 4.x before 4.0.10 does not properly ignore the Host header when absolute-URI is provided, which allows remote attackers to conduct cache-poisoning attacks via an HTTP request.

CVSS3: 8.6
debian
больше 9 лет назад

client_side.cc in Squid before 3.5.18 and 4.x before 4.0.10 does not p ...

oracle-oval
больше 9 лет назад

ELSA-2016-1140: squid34 security update (MODERATE)

EPSS

Процентиль: 97%
0.39528
Средний

8.6 High

CVSS3

Дефекты

CWE-345