CVE-2020-25097
19.03.2021, 05:15
An issue was discovered in Squid through 4.13 and 5.x through 5.0.4. Due to improper input validation, it allows a trusted client to perform HTTP Request Smuggling and access services otherwise forbidden by the security controls. This occurs for certain uri_whitespace configuration settings.Enginsight
Vendor | Product | Version |
---|---|---|
squid-cache | squid | 2.0 ≤ 𝑥 < 4.14 |
squid-cache | squid | 5.0.1 ≤ 𝑥 < 5.0.5 |
debian | debian_linux | 10.0 |
netapp | cloud_manager | - |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Common Weakness Enumeration
References