QID 352267

Date Published: 2021-04-26

QID 352267: Amazon Linux Security Advisory for squid: ALAS2-2021-1631

<DIV ID="issue_overview">
A flaw was found in squid. Due to improper validation while parsing the request URI, squid is vulnerable to HTTP request smuggling. This issue could allow a trusted client to perform an HTTP request smuggling attack and access services otherwise forbidden by squid. The highest threat from this vulnerability is to data confidentiality. (CVE-2020-25097 )
</DIV>

Allows unauthorized disclosure of information; allows unauthorized modification; allows disruption of service.

  • CVSS V3 rated as Critical - 8.6 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Please refer to Amazon advisory: ALAS-2021-1631 for affected packages and patching details, or update with your package manager.
    Vendor References

    CVEs related to QID 352267

    Software Advisories
    Advisory ID Software Component Link
    ALAS-2021-1631 Amazon Linux 2 URL Logo alas.aws.amazon.com/AL2/ALAS-2021-1631.html