CVE-2022-41317

Name
CVE-2022-41317
Description
An issue was discovered in Squid 4.9 through 4.17 and 5.0.6 through 5.6. Due to inconsistent handling of internal URIs, there can be Exposure of Sensitive Information about clients using the proxy via an HTTPS request to an internal cache manager URL. This is fixed in 5.7.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
MISC http://www.squid-cache.org/Versions/v5/changesets/SQUID-2022_1.patch
MISC http://www.squid-cache.org/Versions/v4/changesets/SQUID-2022_1.patch
CONFIRM https://www.openwall.com/lists/oss-security/2022/09/23/1
MISC https://github.com/squid-cache/squid/security/advisories/GHSA-rcg9-7fqm-83mq

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:squid-cache:squid:*:*:*:*:*:*:*:* squid >= 4.9 <= 4.17
cpe:2.3:a:squid-cache:squid:*:*:*:*:*:*:*:* squid >= 5.0.6 < 5.7

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
squid 3.15-main 5.2-r1 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
squid 3.16-main 5.5-r1 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable