Back

MEDIUM

squid: exposure of sensitive information in cache manager

Published Dec 25, 2022

Description

An issue was discovered in Squid 4.9 through 4.17 and 5.0.6 through 5.6. Due to inconsistent handling of internal URIs, there can be Exposure of Sensitive Information about clients using the proxy via an HTTPS request to an internal cache manager URL. This is fixed in 5.7.

Affected products

Remediation

Red Hat mitigation

Adding the following line to the squid.conf file is a workaround: acl manager url_regex +i ^[^:]+://[^/]+/squid-internal-mgr/

Metrics

Weaknesses (2)

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Dec 25, 2022
Updated Apr 14, 2025
Reserved Sep 23, 2022
CISA Vulnrichment
Updated Apr 14, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Sep 23, 2022