Information Exposure Vulnerability in Squid Proxy Server
CVE-2022-41317

6.5MEDIUM

Key Information:

Status
Vendor
CVE Published:
25 December 2022

What is CVE-2022-41317?

An issue was identified in versions 4.9 through 4.17 and 5.0.6 through 5.6 of the Squid Proxy Server, caused by inconsistent handling of internal URIs. This flaw can lead to the exposure of sensitive client information when an HTTPS request is made to an internal cache manager URL. The vulnerability has been addressed in Squid version 5.7, emphasizing the importance of upgrading to ensure the security of the proxy environment.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.