Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-41317

Опубликовано: 23 сент. 2022
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

An issue was discovered in Squid 4.9 through 4.17 and 5.0.6 through 5.6. Due to inconsistent handling of internal URIs, there can be Exposure of Sensitive Information about clients using the proxy via an HTTPS request to an internal cache manager URL. This is fixed in 5.7.

A flaw was found in squid. A trusted client can directly access the cache manager information, bypassing the manager ACL protection and resulting in information disclosure.

Меры по смягчению последствий

Adding the following line to the squid.conf file is a workaround: acl manager url_regex +i ^[^:]+://[^/]+/squid-internal-mgr/

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6squidNot affected
Red Hat Enterprise Linux 6squid34Not affected
Red Hat Enterprise Linux 7squidNot affected
Red Hat Enterprise Linux 8squid:4/squidWill not fix
Red Hat Enterprise Linux 9squidWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-284->CWE-200
https://bugzilla.redhat.com/show_bug.cgi?id=2129770squid: exposure of sensitive information in cache manager

EPSS

Процентиль: 76%
0.01036
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 2 лет назад

An issue was discovered in Squid 4.9 through 4.17 and 5.0.6 through 5.6. Due to inconsistent handling of internal URIs, there can be Exposure of Sensitive Information about clients using the proxy via an HTTPS request to an internal cache manager URL. This is fixed in 5.7.

CVSS3: 6.5
nvd
больше 2 лет назад

An issue was discovered in Squid 4.9 through 4.17 and 5.0.6 through 5.6. Due to inconsistent handling of internal URIs, there can be Exposure of Sensitive Information about clients using the proxy via an HTTPS request to an internal cache manager URL. This is fixed in 5.7.

CVSS3: 6.5
debian
больше 2 лет назад

An issue was discovered in Squid 4.9 through 4.17 and 5.0.6 through 5. ...

CVSS3: 6.5
redos
больше 2 лет назад

Уязвимость SQUID

CVSS3: 6.5
fstec
больше 2 лет назад

Уязвимость кэширующего прокси-сервера Squid, связанная с неправильным контролем доступа, позволяющая нарушителю получить доступ к конфиденциальной информации

EPSS

Процентиль: 76%
0.01036
Низкий

6.5 Medium

CVSS3