Access Bypass Vulnerability in Squid Proxy Server by Squid Software Foundation
CVE-2019-12524
9.8CRITICAL
What is CVE-2019-12524?
A vulnerability in Squid Proxy Server allows attackers to bypass access restrictions set by url_regex rules. Through URL encoding techniques, attackers can craft requests that deceive the server into permitting access to the Cache Manager, which is intended to be a restricted resource. This could lead to unauthorized information disclosure about server configurations and operations.