CVE-2020-15049

Description

An issue was discovered in http/ContentLengthInterpreter.cc in Squid before 4.12 and 5.x before 5.0.3. A Request Smuggling and Poisoning attack can succeed against the HTTP cache. The client sends an HTTP request with a Content-Length header containing + - or an uncommon shell whitespace character prefix to the length field-value.

Risk Information

Base Score
8.8
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
15.653

Associated Vulnerability

VulnerabilityOS Platform
Multiple Vulnerabilities are affected in IBM Security Guardium 10.5Windows
Multiple Vulnerabilities are affected in IBM Security Guardium 10.6Windows
Multiple Vulnerabilities are affected in IBM Security Guardium 11.1Windows
Multiple Vulnerabilities are affected in IBM Security Guardium 11.2Windows
Multiple Vulnerabilities are affected in IBM Security Guardium 11.3Windows
Multiple Vulnerabilities are affected in IBM Security Guardium 11.0Windows
Web proxy cache server (USN-4551-1) squid_3.5.27-1ubuntu1.9_i386.debLinux
Web proxy cache server (USN-4551-1) squid_3.5.27-1ubuntu1.9_amd64.debLinux
Web proxy cache server (USN-4551-1) squid_3.5.12-1ubuntu7.15_i386.debLinux
Web proxy cache server (USN-4551-1) squid_3.5.12-1ubuntu7.15_amd64.debLinux
(RHSA-2020:4082) squid security update squid-3.5.20-17.el7_9.4.x86_64.rpmLinux
(RHSA-2020:4082) squid security update squid-migration-script-3.5.20-17.el7_9.4.x86_64.rpmLinux
(RHSA-2020:4082) squid security update squid-sysvinit-3.5.20-17.el7_9.4.x86_64.rpmLinux
(RHSA-2020:4743) squid:4 security, bug fix, and enhancement update squid-4.11-3.module+el8.3.0+7851+7808b5f9.x86_64.rpmLinux
(RHSA-2020:4743) squid:4 security, bug fix, and enhancement update squid-debugsource-4.11-3.module+el8.3.0+7851+7808b5f9.x86_64.rpmLinux
Squid update (ELSA-2020-4082) squid-3.5.20-17.el7_9.4.x86_64.rpmLinux
Squid-migration-script update (ELSA-2020-4082) squid-migration-script-3.5.20-17.el7_9.4.x86_64.rpmLinux
Squid-sysvinit update (ELSA-2020-4082) squid-sysvinit-3.5.20-17.el7_9.4.x86_64.rpmLinux
Web proxy cache server (USN-4895-1) squid_4.10-1ubuntu1.3_amd64.debLinux
Web proxy cache server (USN-4895-1) squid_4.13-1ubuntu2.1_amd64.debLinux
Web proxy cache server (USN-4895-1) squid_3.5.12-1ubuntu7.16_i386.debLinux
Web proxy cache server (USN-4895-1) squid_3.5.12-1ubuntu7.16_amd64.debLinux
Web proxy cache server (USN-4895-1) squid_3.5.27-1ubuntu1.10_i386.debLinux
Web proxy cache server (USN-4895-1) squid_3.5.27-1ubuntu1.10_amd64.debLinux
(CESA-2020:4082) squid security update squid-3.5.20-17.el7_9.4.x86_64.rpmLinux
(CESA-2020:4082) squid security update squid-migration-script-3.5.20-17.el7_9.4.x86_64.rpmLinux
(CESA-2020:4082) squid security update squid-sysvinit-3.5.20-17.el7_9.4.x86_64.rpmLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234