Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-46846

Опубликовано: 19 окт. 2023
Источник: redhat
CVSS3: 9.3

Описание

SQUID is vulnerable to HTTP request smuggling, caused by chunked decoder lenience, allows a remote attacker to perform Request/Response smuggling past firewall and frontend security systems.

Отчет

This attack is limited to the HTTP/1.1 and ICAP protocols which support receiving Transfer-Encoding:chunked.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6squidWill not fix
Red Hat Enterprise Linux 6squid34Will not fix
Red Hat Enterprise Linux 7 Extended Lifecycle SupportsquidFixedRHSA-2024:1104916.12.2024
Red Hat Enterprise Linux 8squidFixedRHSA-2023:626702.11.2023
Red Hat Enterprise Linux 8squidFixedRHSA-2023:721314.11.2023
Red Hat Enterprise Linux 8.1 Update Services for SAP SolutionssquidFixedRHSA-2023:681008.11.2023
Red Hat Enterprise Linux 8.2 Advanced Update SupportsquidFixedRHSA-2023:680308.11.2023
Red Hat Enterprise Linux 8.2 Telecommunications Update ServicesquidFixedRHSA-2023:680308.11.2023
Red Hat Enterprise Linux 8.2 Update Services for SAP SolutionssquidFixedRHSA-2023:680308.11.2023
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportsquidFixedRHSA-2023:680408.11.2023

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-444
https://bugzilla.redhat.com/show_bug.cgi?id=2245910squid: Request/Response smuggling in HTTP/1.1 and ICAP

9.3 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.3
ubuntu
больше 1 года назад

SQUID is vulnerable to HTTP request smuggling, caused by chunked decoder lenience, allows a remote attacker to perform Request/Response smuggling past firewall and frontend security systems.

CVSS3: 9.3
nvd
больше 1 года назад

SQUID is vulnerable to HTTP request smuggling, caused by chunked decoder lenience, allows a remote attacker to perform Request/Response smuggling past firewall and frontend security systems.

CVSS3: 9.3
debian
больше 1 года назад

SQUID is vulnerable to HTTP request smuggling, caused by chunked decod ...

oracle-oval
4 месяца назад

ELSA-2024-11049: squid security update (IMPORTANT)

CVSS3: 5.3
fstec
больше 1 года назад

Уязвимость декодера chunked прокси-сервера Squid, позволяющая нарушителю взаимодействовать с сервером напрямую

9.3 Critical

CVSS3

Уязвимость CVE-2023-46846