CVE-2019-18677: CSRF
An issue was discovered in Squid 3.x and 4.x through 4.8 when the appenddomain setting is used (because the appended characters do not properly interact with hostname length restrictions). Due to incorrect message processing, it can inappropriately redirect traffic to origins it should not be delivered to.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2019-18677.
What is the severity of CVE-2019-18677?
The severity of CVE-2019-18677 is medium.
What is the affected software?
The affected software is Squid 3.x and 4.x through 4.8.
How does the vulnerability CVE-2019-18677 impact the affected software?
The vulnerability CVE-2019-18677 can inappropriately redirect traffic to origins it should not be delivered to due to incorrect message processing.
Is there a fix available for CVE-2019-18677?
Yes, a fix is available for CVE-2019-18677. Users should update to version 4.9-2ubuntu1 or later for Ubuntu, or apply the appropriate patches for other affected systems.