Описание
Squid is a caching proxy for the Web. In Squid versions prior to 7.2, a failure to redact HTTP authentication credentials in error handling allows information disclosure. The vulnerability allows a script to bypass browser security protections and learn the credentials a trusted client uses to authenticate. This potentially allows a remote client to identify security tokens or credentials used internally by a web application using Squid for backend load balancing. These attacks do not require Squid to be configured with HTTP authentication. The vulnerability is fixed in version 7.2. As a workaround, disable debug information in administrator mailto links generated by Squid by configuring squid.conf with email_err_data off.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | pending | 6.13-1ubuntu5 |
| esm-infra/focal | released | 4.10-1ubuntu1.13+esm1 |
| jammy | released | 5.9-0ubuntu0.22.04.4 |
| noble | released | 6.13-0ubuntu0.24.04.3 |
| plucky | released | 6.13-1ubuntu1.2 |
| questing | released | 6.13-1ubuntu4.1 |
| upstream | released | 7.2 |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| devel | DNE | |
| esm-infra/bionic | released | 3.5.27-1ubuntu1.14+esm4 |
| esm-infra/xenial | released | 3.5.12-1ubuntu7.16+esm5 |
| jammy | DNE | |
| noble | DNE | |
| plucky | DNE | |
| questing | DNE | |
| upstream | needs-triage |
Показывать по
Ссылки на источники
10 Critical
CVSS3
Связанные уязвимости
Squid is a caching proxy for the Web. In Squid versions prior to 7.2, a failure to redact HTTP authentication credentials in error handling allows information disclosure. The vulnerability allows a script to bypass browser security protections and learn the credentials a trusted client uses to authenticate. This potentially allows a remote client to identify security tokens or credentials used internally by a web application using Squid for backend load balancing. These attacks do not require Squid to be configured with HTTP authentication. The vulnerability is fixed in version 7.2. As a workaround, disable debug information in administrator mailto links generated by Squid by configuring squid.conf with email_err_data off.
Squid vulnerable to information disclosure via authentication credential leakage in error handling
Squid is a caching proxy for the Web. In Squid versions prior to 7.2, ...
10 Critical
CVSS3