PT-2021-5368 · Squid · Squid+1
Jean-Paul Larocque
·
Published
2021-10-04
·
Updated
2022-03-31
·
CVE-2021-41611
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Squid versions 5.0.6 through 5.1.x
Description
An issue was discovered in Squid when validating an origin server or peer certificate, which may incorrectly classify certain certificates as trusted. This problem allows a remote server to obtain security trust improperly, and this indication of trust may be passed along to clients, allowing access to unsafe or hijacked services. The vulnerability is related to errors in certificate authentication and can be exploited by a remote attacker to perform a man-in-the-middle attack.
Recommendations
For Squid versions 5.0.6 through 5.1.x, update to version 5.2 or later to resolve the issue. As a temporary workaround, consider restricting the use of certificate validation until a patch is available. Avoid using the vulnerable certificate validation mechanism in Squid until the issue is resolved.
Fix
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Squid
Squid Cache