Missing Authentication for Critical Function Affecting squid:4/libecap-devel package, versions <0:1.0.1-2.module_el8.6.0+2741+01592ae8


Severity

Recommended
medium

Based on AlmaLinux security rating

    Threat Intelligence

    EPSS
    1.11% (85th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk ID SNYK-ALMALINUX8-SQUID-5617034
  • published 28 May 2023
  • disclosed 3 Nov 2020

How to fix?

Upgrade AlmaLinux:8 squid:4/libecap-devel to version 0:1.0.1-2.module_el8.6.0+2741+01592ae8 or higher.
This issue was patched in ALSA-2020:4743.

NVD Description

Note: Versions mentioned in the description apply only to the upstream squid:4/libecap-devel package and not the squid:4/libecap-devel package as distributed by AlmaLinux. See How to fix? for AlmaLinux:8 relevant fixed versions and status.

An issue was discovered in Squid through 4.7. When handling requests from users, Squid checks its rules to see if the request should be denied. Squid by default comes with rules to block access to the Cache Manager, which serves detailed server information meant for the maintainer. This rule is implemented via url_regex. The handler for url_regex rules URL decodes an incoming request. This allows an attacker to encode their URL to bypass the url_regex check, and gain access to the blocked resource.

CVSS Scores

version 3.1
Expand this section

NVD

9.8 critical
  • Attack Vector (AV)
    Network
  • Attack Complexity (AC)
    Low
  • Privileges Required (PR)
    None
  • User Interaction (UI)
    None
  • Scope (S)
    Unchanged
  • Confidentiality (C)
    High
  • Integrity (I)
    High
  • Availability (A)
    High
Expand this section

Red Hat

5.3 medium