Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-19131

Опубликовано: 31 окт. 2018
Источник: redhat
CVSS3: 5.6
EPSS Средний

Описание

Squid before 4.4 has XSS via a crafted X.509 certificate during HTTP(S) error page generation for certificate errors.

A Cross-Site Scripting vulnerability has been discovered in squid in the way X.509 certificates fields are displayed in some error pages. An attacker who can control the certificate of the origin content server may use this flaw to inject scripting code in the squid generated page, which is executed on the client's browser.

Меры по смягчению последствий

Remove %D error page macro from ERR_SECURE_CONNECT_FAIL pages found under /usr/share/squid/errors/ and any custom error pages.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5squidNot affected
Red Hat Enterprise Linux 6squidWill not fix
Red Hat Enterprise Linux 6squid34Will not fix
Red Hat Enterprise Linux 7squidWill not fix
Red Hat Enterprise Linux 8squidNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=1645146squid: Cross-Site Scripting when generating HTTPS response messages about TLS errors

EPSS

Процентиль: 93%
0.10782
Средний

5.6 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.1
ubuntu
около 7 лет назад

Squid before 4.4 has XSS via a crafted X.509 certificate during HTTP(S) error page generation for certificate errors.

CVSS3: 6.1
nvd
около 7 лет назад

Squid before 4.4 has XSS via a crafted X.509 certificate during HTTP(S) error page generation for certificate errors.

CVSS3: 6.1
debian
около 7 лет назад

Squid before 4.4 has XSS via a crafted X.509 certificate during HTTP(S ...

suse-cvrf
около 7 лет назад

Security update for squid3

CVSS3: 6.1
github
больше 3 лет назад

Squid before 4.4 has XSS via a crafted X.509 certificate during HTTP(S) error page generation for certificate errors.

EPSS

Процентиль: 93%
0.10782
Средний

5.6 Medium

CVSS3