6.5
CVE-2020-15811
- EPSS 4.24%
- Veröffentlicht 02.09.2020 17:15:11
- Zuletzt bearbeitet 21.11.2024 05:06:13
- Erkennungen
An issue was discovered in Squid before 4.13 and 5.x before 5.0.4. Due to incorrect data validation, HTTP Request Splitting attacks may succeed against HTTP and HTTPS traffic. This leads to cache poisoning. This allows any client, including browser scripts, to bypass local security and poison the browser cache and any downstream caches with content from an arbitrary source. Squid uses a string search instead of parsing the Transfer-Encoding header to find chunked encoding. This allows an attacker to hide a second request inside Transfer-Encoding: it is interpreted by Squid as chunked and split out into a second request delivered upstream. Squid will then deliver two distinct responses to the client, corrupting any downstream caches.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Squid-cache ≫ Squid Version < 4.13
Squid-cache ≫ Squid Version >= 5.0 < 5.0.4
Canonical ≫ Ubuntu Linux Version 16.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 18.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 20.04 SwEdition lts
Debian ≫ Debian Linux Version 9.0
Debian ≫ Debian Linux Version 10.0
Fedoraproject ≫ Fedora Version 31
Fedoraproject ≫ Fedora Version 32
Fedoraproject ≫ Fedora Version 33
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 4.24% | 0.897 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
|
| NIST | 4 | 8 | 2.9 |
AV:N/AC:L/Au:S/C:N/I:P/A:N
|
CWE-697 Incorrect Comparison
The product compares two entities in a security-relevant context, but the comparison is incorrect.
http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00012.html
http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00017.html
https://lists.debian.org/debian-lts-announce/2020/10/msg00005.html
https://usn.ubuntu.com/4551-1/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BE6FKUN7IGTIR2MEEMWYDT7N5EJJLZI2/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BMTFLVB7GLRF2CKGFPZ4G4R5DIIPHWI3/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HJJDI7JQFGQLVNCKMVY64LAFMKERAOK7/
https://security.netapp.com/advisory/ntap-20210219-0007/
https://security.netapp.com/advisory/ntap-20210226-0006/
https://security.netapp.com/advisory/ntap-20210226-0007/
https://usn.ubuntu.com/4477-1/
https://www.debian.org/security/2020/dsa-4751
https://github.com/squid-cache/squid/security/advisories/GHSA-c7p8-xqhm-49wv