Логотип exploitDog
bind:CVE-2019-12524
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2019-12524

Количество 11

Количество 11

ubuntu логотип

CVE-2019-12524

больше 5 лет назад

An issue was discovered in Squid through 4.7. When handling requests from users, Squid checks its rules to see if the request should be denied. Squid by default comes with rules to block access to the Cache Manager, which serves detailed server information meant for the maintainer. This rule is implemented via url_regex. The handler for url_regex rules URL decodes an incoming request. This allows an attacker to encode their URL to bypass the url_regex check, and gain access to the blocked resource.

CVSS3: 9.8
EPSS: Низкий
redhat логотип

CVE-2019-12524

больше 5 лет назад

An issue was discovered in Squid through 4.7. When handling requests from users, Squid checks its rules to see if the request should be denied. Squid by default comes with rules to block access to the Cache Manager, which serves detailed server information meant for the maintainer. This rule is implemented via url_regex. The handler for url_regex rules URL decodes an incoming request. This allows an attacker to encode their URL to bypass the url_regex check, and gain access to the blocked resource.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2019-12524

больше 5 лет назад

An issue was discovered in Squid through 4.7. When handling requests from users, Squid checks its rules to see if the request should be denied. Squid by default comes with rules to block access to the Cache Manager, which serves detailed server information meant for the maintainer. This rule is implemented via url_regex. The handler for url_regex rules URL decodes an incoming request. This allows an attacker to encode their URL to bypass the url_regex check, and gain access to the blocked resource.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2019-12524

больше 5 лет назад

An issue was discovered in Squid through 4.7. When handling requests f ...

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-wwv6-9vqw-fwxx

около 3 лет назад

An issue was discovered in Squid through 4.7. When handling requests from users, Squid checks its rules to see if the request should be denied. Squid by default comes with rules to block access to the Cache Manager, which serves detailed server information meant for the maintainer. This rule is implemented via url_regex. The handler for url_regex rules URL decodes an incoming request. This allows an attacker to encode their URL to bypass the url_regex check, and gain access to the blocked resource.

EPSS: Низкий
fstec логотип

BDU:2020-02595

больше 5 лет назад

Уязвимость прокси-сервера Squid, связанная с отсутствием механизма аутентификации для url_regex, позволяющая нарушителю получить доступ к заблокированному ресурсу

CVSS2: 7.5
EPSS: Низкий
oracle-oval логотип

ELSA-2022-22254

почти 3 года назад

ELSA-2022-22254: squid security update (IMPORTANT)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2020:1227-1

больше 5 лет назад

Security update for squid

EPSS: Низкий
rocky логотип

RLSA-2020:4743

почти 5 лет назад

Moderate: squid:4 security, bug fix, and enhancement update

EPSS: Низкий
oracle-oval логотип

ELSA-2020-4743

почти 5 лет назад

ELSA-2020-4743: squid:4 security, bug fix, and enhancement update (MODERATE)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2020:14460-1

почти 5 лет назад

Security update for squid3

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2019-12524

An issue was discovered in Squid through 4.7. When handling requests from users, Squid checks its rules to see if the request should be denied. Squid by default comes with rules to block access to the Cache Manager, which serves detailed server information meant for the maintainer. This rule is implemented via url_regex. The handler for url_regex rules URL decodes an incoming request. This allows an attacker to encode their URL to bypass the url_regex check, and gain access to the blocked resource.

CVSS3: 9.8
1%
Низкий
больше 5 лет назад
redhat логотип
CVE-2019-12524

An issue was discovered in Squid through 4.7. When handling requests from users, Squid checks its rules to see if the request should be denied. Squid by default comes with rules to block access to the Cache Manager, which serves detailed server information meant for the maintainer. This rule is implemented via url_regex. The handler for url_regex rules URL decodes an incoming request. This allows an attacker to encode their URL to bypass the url_regex check, and gain access to the blocked resource.

CVSS3: 5.3
1%
Низкий
больше 5 лет назад
nvd логотип
CVE-2019-12524

An issue was discovered in Squid through 4.7. When handling requests from users, Squid checks its rules to see if the request should be denied. Squid by default comes with rules to block access to the Cache Manager, which serves detailed server information meant for the maintainer. This rule is implemented via url_regex. The handler for url_regex rules URL decodes an incoming request. This allows an attacker to encode their URL to bypass the url_regex check, and gain access to the blocked resource.

CVSS3: 9.8
1%
Низкий
больше 5 лет назад
debian логотип
CVE-2019-12524

An issue was discovered in Squid through 4.7. When handling requests f ...

CVSS3: 9.8
1%
Низкий
больше 5 лет назад
github логотип
GHSA-wwv6-9vqw-fwxx

An issue was discovered in Squid through 4.7. When handling requests from users, Squid checks its rules to see if the request should be denied. Squid by default comes with rules to block access to the Cache Manager, which serves detailed server information meant for the maintainer. This rule is implemented via url_regex. The handler for url_regex rules URL decodes an incoming request. This allows an attacker to encode their URL to bypass the url_regex check, and gain access to the blocked resource.

1%
Низкий
около 3 лет назад
fstec логотип
BDU:2020-02595

Уязвимость прокси-сервера Squid, связанная с отсутствием механизма аутентификации для url_regex, позволяющая нарушителю получить доступ к заблокированному ресурсу

CVSS2: 7.5
1%
Низкий
больше 5 лет назад
oracle-oval логотип
ELSA-2022-22254

ELSA-2022-22254: squid security update (IMPORTANT)

почти 3 года назад
suse-cvrf логотип
SUSE-SU-2020:1227-1

Security update for squid

больше 5 лет назад
rocky логотип
RLSA-2020:4743

Moderate: squid:4 security, bug fix, and enhancement update

почти 5 лет назад
oracle-oval логотип
ELSA-2020-4743

ELSA-2020-4743: squid:4 security, bug fix, and enhancement update (MODERATE)

почти 5 лет назад
suse-cvrf логотип
SUSE-SU-2020:14460-1

Security update for squid3

почти 5 лет назад

Уязвимостей на страницу