QID 375397

Date Published: 2021-03-24

QID 375397: Squid HTTP Request Smuggling Vulnerability (SQUID-2020:11)

Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. It reduces bandwidth and improves response times by caching and reusing frequently-requested web pages.

Affected Versions:
Squid version 2.0 to 4.13
Squid version 5.0.1 to 5.0.4

QID Detection Logic:
This QID checks for vulnerable version of Squid.

Successful exploitation could allow a trusted client to perform HTTP Request Smuggling and access services otherwise forbidden by Squid security controls.

  • CVSS V3 rated as Critical - 8.6 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Customers are advised to upgrade to a fixed version of Squid versions 4.14 and 5.0.5 to remediate this vulnerability.

    CVEs related to QID 375397

    Software Advisories
    Advisory ID Software Component Link
    SQUID-2020:11 URL Logo www.squid-cache.org/Versions/v4/changesets/SQUID-2020_11.patch