PT-2021-5368 · Squid · Squid+1

Jean-Paul Larocque

·

Published

2021-10-04

·

Updated

2022-03-31

·

CVE-2021-41611

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Squid versions 5.0.6 through 5.1.x
Description An issue was discovered in Squid when validating an origin server or peer certificate, which may incorrectly classify certain certificates as trusted. This problem allows a remote server to obtain security trust improperly, and this indication of trust may be passed along to clients, allowing access to unsafe or hijacked services. The vulnerability is related to errors in certificate authentication and can be exploited by a remote attacker to perform a man-in-the-middle attack.
Recommendations For Squid versions 5.0.6 through 5.1.x, update to version 5.2 or later to resolve the issue. As a temporary workaround, consider restricting the use of certificate validation until a patch is available. Avoid using the vulnerable certificate validation mechanism in Squid until the issue is resolved.

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-06198
CVE-2021-41611
GHSA-47M4-G3MV-9Q5R

Affected Products

Squid
Squid Cache