CVE-2022-41317
Summary
| CVE | CVE-2022-41317 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-12-25 19:15:00 UTC |
| Updated | 2023-08-08 14:22:00 UTC |
| Description | An issue was discovered in Squid 4.9 through 4.17 and 5.0.6 through 5.6. Due to inconsistent handling of internal URIs, there can be Exposure of Sensitive Information about clients using the proxy via an HTTPS request to an internal cache manager URL. This is fixed in 5.7. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| www.squid-cache.org/Versions/v5/changesets/SQUID-2022_1.patch |
MISC |
www.squid-cache.org |
|
| oss-security - Fwd: [ADVISORY] SQUID-2022:1 Exposure of Sensitive Information in
Cache Manager |
CONFIRM |
www.openwall.com |
|
| www.squid-cache.org/Versions/v4/changesets/SQUID-2022_1.patch |
MISC |
www.squid-cache.org |
|
| SQUID-2022:1 Exposure of Sensitive Information in Cache Manager · Advisory · squid-cache/squid · GitHub |
MISC |
github.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 181132 Debian Security Update for squid (DLA 3151-1)
- 181146 Debian Security Update for squid (DSA 5258-1)
- 184816 Debian Security Update for squid (CVE-2022-41317)
- 198961 Ubuntu Security Notification for Squid Vulnerabilities (USN-5641-1)
- 283170 Fedora Security Update for squid (FEDORA-2022-c8cad41c95)
- 283171 Fedora Security Update for squid (FEDORA-2022-23e6ee1fb9)
- 354752 Amazon Linux Security Advisory for squid : ALAS-2023-1687
- 354783 Amazon Linux Security Advisory for squid : ALAS2-2023-1950
- 356199 Amazon Linux Security Advisory for squid : ALASSQUID4-2023-009
- 356205 Amazon Linux Security Advisory for squid : ALASSQUID4-2023-002
- 356506 Amazon Linux Security Advisory for squid : ALAS2SQUID4-2023-002
- 356609 Amazon Linux Security Advisory for squid : ALAS2SQUID4-2023-010
- 505939 Alpine Linux Security Update for squid
- 672417 EulerOS Security Update for squid (EulerOS-SA-2022-2807)
- 690944 Free Berkeley Software Distribution (FreeBSD) Security Update for squid (f9ada0b5-3d80-11ed-9330-080027f5fec9)
- 752660 SUSE Enterprise Linux Security Update for squid (SUSE-SU-2022:3533-1)
- 752662 SUSE Enterprise Linux Security Update for squid (SUSE-SU-2022:3532-1)
- 752677 SUSE Enterprise Linux Security Update for squid (SUSE-SU-2022:3596-1)
- 753450 SUSE Enterprise Linux Security Update for squid (SUSE-SU-2022:3531-1)