Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-15811

Опубликовано: 23 авг. 2020
Источник: redhat
CVSS3: 9.6
EPSS Низкий

Описание

An issue was discovered in Squid before 4.13 and 5.x before 5.0.4. Due to incorrect data validation, HTTP Request Splitting attacks may succeed against HTTP and HTTPS traffic. This leads to cache poisoning. This allows any client, including browser scripts, to bypass local security and poison the browser cache and any downstream caches with content from an arbitrary source. Squid uses a string search instead of parsing the Transfer-Encoding header to find chunked encoding. This allows an attacker to hide a second request inside Transfer-Encoding: it is interpreted by Squid as chunked and split out into a second request delivered upstream. Squid will then deliver two distinct responses to the client, corrupting any downstream caches.

A flaw was found in squid. Due to incorrect data validation, an HTTP Request Splitting attack against HTTP and HTTPS traffic is possible leading to cache poisoning. The highest threat from this vulnerability is to data confidentiality and integrity.

Меры по смягчению последствий

Disable the relaxed HTTP parser in squid.conf:

relaxed_header_parser off

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5squidOut of support scope
Red Hat Enterprise Linux 6squidOut of support scope
Red Hat Enterprise Linux 6squid34Out of support scope
Red Hat Enterprise Linux 7squidFixedRHSA-2020:408230.09.2020
Red Hat Enterprise Linux 8squidFixedRHSA-2020:362303.09.2020
Red Hat Enterprise Linux 8.0 Update Services for SAP SolutionssquidFixedRHSA-2020:362303.09.2020
Red Hat Enterprise Linux 8.1 Extended Update SupportsquidFixedRHSA-2020:362303.09.2020

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-444
https://bugzilla.redhat.com/show_bug.cgi?id=1871702squid: HTTP Request Splitting could result in cache poisoning

EPSS

Процентиль: 55%
0.00328
Низкий

9.6 Critical

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
почти 5 лет назад

An issue was discovered in Squid before 4.13 and 5.x before 5.0.4. Due to incorrect data validation, HTTP Request Splitting attacks may succeed against HTTP and HTTPS traffic. This leads to cache poisoning. This allows any client, including browser scripts, to bypass local security and poison the browser cache and any downstream caches with content from an arbitrary source. Squid uses a string search instead of parsing the Transfer-Encoding header to find chunked encoding. This allows an attacker to hide a second request inside Transfer-Encoding: it is interpreted by Squid as chunked and split out into a second request delivered upstream. Squid will then deliver two distinct responses to the client, corrupting any downstream caches.

CVSS3: 6.5
nvd
почти 5 лет назад

An issue was discovered in Squid before 4.13 and 5.x before 5.0.4. Due to incorrect data validation, HTTP Request Splitting attacks may succeed against HTTP and HTTPS traffic. This leads to cache poisoning. This allows any client, including browser scripts, to bypass local security and poison the browser cache and any downstream caches with content from an arbitrary source. Squid uses a string search instead of parsing the Transfer-Encoding header to find chunked encoding. This allows an attacker to hide a second request inside Transfer-Encoding: it is interpreted by Squid as chunked and split out into a second request delivered upstream. Squid will then deliver two distinct responses to the client, corrupting any downstream caches.

CVSS3: 6.5
debian
почти 5 лет назад

An issue was discovered in Squid before 4.13 and 5.x before 5.0.4. Due ...

CVSS3: 6.5
fstec
почти 5 лет назад

Уязвимость прокси-сервера Squid, связанная с непринятием мер по обработке последовательностей CRLF в HTTP-заголовках, позволяющая нарушителю внедрить произвольные HTTP-заголовки

rocky
почти 5 лет назад

Important: squid:4 security update

EPSS

Процентиль: 55%
0.00328
Низкий

9.6 Critical

CVSS3