CVE-2019-12523: Critical severity Squid-Cache Squid vulnerability
An issue was discovered in Squid before 4.9. When handling a URN request, a corresponding HTTP request is made. This HTTP request doesn't go through the access checks that incoming HTTP requests go through. This causes all access checks to be bypassed and allows access to restricted HTTP servers, e.g., an attacker can connect to HTTP servers that only listen on localhost.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2019-12523?
CVE-2019-12523 is a vulnerability in Squid before version 4.9 that allows bypassing access checks and accessing restricted HTTP servers.
What is the severity of CVE-2019-12523?
The severity of CVE-2019-12523 is critical with a CVSS score of 9.1.
How does CVE-2019-12523 impact Squid?
CVE-2019-12523 impacts Squid by allowing access to restricted HTTP servers and bypassing access checks.
What versions of Squid are affected by CVE-2019-12523?
Versions before 4.9 of Squid are affected by CVE-2019-12523.
How do I fix CVE-2019-12523?
Update Squid to version 4.9 or later to fix CVE-2019-12523.