PT-2020-5788 · Squid+8 · Squid+9
Published
2020-03-14
·
Updated
2025-11-07
·
CVE-2019-18860
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Squid versions prior to 4.9
Squid versions 4.6 through 4.6-1+deb10u3
Squid versions 3.5.23-5+deb9u2 and earlier
Squid version 4.10-alt1
Squid versions 4.16-1.5
Description
Squid, a high-performance proxy caching server, is affected by multiple security issues. These include incorrect input validation and URL request handling, which could allow bypassing access restrictions for restricted HTTP servers and cause a denial-of-service. Additionally, the software mishandles HTML in the
host parameter to cachemgr.cgi, potentially leading to cross-site scripting (XSS). The vulnerabilities can also result in cache poisoning and incomplete validation of hostnames in cachemgr.cgi. The cachemgr.cgi script is vulnerable due to improper handling of HTML in the host parameter when certain web browsers are used. The API endpoint /cachemgr.cgi is affected, with the host parameter being the vulnerable input.Recommendations
Upgrade to Squid version 4.9 or later.
Upgrade to Squid version 4.6-1+deb10u3 or later.
Upgrade to Squid version 3.5.23-5+deb9u2 or later.
Upgrade to Squid version 4.10-alt1.
Upgrade to Squid version 4.16-1.5.
Fix
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Almalinux
Centos
Linuxmint
Red Hat
Rocky Linux
Squid
Squid Cache
Suse
Ubuntu