← Back

CVE-2022-41317

nvd nist
Published: Dec 25, 2022Modified: Jun 17, 2026

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitability: 2.8 / Impact: 3.6
Source: NVD

Description

An issue was discovered in Squid 4.9 through 4.17 and 5.0.6 through 5.6. Due to inconsistent handling of internal URIs, there can be Exposure of Sensitive Information about clients using the proxy via an HTTPS request to an internal cache manager URL. This is fixed in 5.7.

Affected (2)

Products: Squid Cache: Squid
1 product
Squid
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Squid Cache
From 4.9 to 4.17
From 5.0.6 to 5.7

References (8)

Source: cve@mitre.org
MitigationPatchThird Party Advisory
Source: cve@mitre.org
Mailing ListMitigationPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
MitigationPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListMitigationPatchThird Party Advisory

Timeline

No history available yet.