PT-2020-5788 · Squid+8 · Squid+9

Published

2020-03-14

·

Updated

2025-11-07

·

CVE-2019-18860

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Squid versions prior to 4.9 Squid versions 4.6 through 4.6-1+deb10u3 Squid versions 3.5.23-5+deb9u2 and earlier Squid version 4.10-alt1 Squid versions 4.16-1.5
Description Squid, a high-performance proxy caching server, is affected by multiple security issues. These include incorrect input validation and URL request handling, which could allow bypassing access restrictions for restricted HTTP servers and cause a denial-of-service. Additionally, the software mishandles HTML in the host parameter to cachemgr.cgi, potentially leading to cross-site scripting (XSS). The vulnerabilities can also result in cache poisoning and incomplete validation of hostnames in cachemgr.cgi. The cachemgr.cgi script is vulnerable due to improper handling of HTML in the host parameter when certain web browsers are used. The API endpoint /cachemgr.cgi is affected, with the host parameter being the vulnerable input.
Recommendations Upgrade to Squid version 4.9 or later. Upgrade to Squid version 4.6-1+deb10u3 or later. Upgrade to Squid version 3.5.23-5+deb9u2 or later. Upgrade to Squid version 4.10-alt1. Upgrade to Squid version 4.16-1.5.

Fix

Special Elements Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2020:4743
ALT-PU-2020-1479
ALT-PU-2020-1494
BDU:2021-01750
CESA-2020_4743
CVE-2019-18860
DLA-2278-1
DSA-4732-1
OPENSUSE-SU-2020:0623-1
OPENSUSE-SU-2020_0623-1
OPENSUSE-SU-2024:11403-1
RHSA-2020:4743
RHSA-2020_4743
RLSA-2020:4743
SUSE-SU-2020:1134-1
SUSE-SU-2020:1156-1
SUSE-SU-2020:14460-1
SUSE-SU-2020:1803-1
SUSE-SU-2020_1803-1
USN-4356-1

Affected Products

Alt Linux
Almalinux
Centos
Linuxmint
Red Hat
Rocky Linux
Squid
Squid Cache
Suse
Ubuntu