6.1
CVSSv3

CVE-2019-13345

Published: 05/07/2019 Updated: 07/11/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

The cachemgr.cgi web module of Squid up to and including 4.7 has XSS via the user_name or auth parameter.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

squid-cache squid

debian debian linux 8.0

Vendor Advisories

Debian Bug report logs - #931478 squid: CVE-2019-13345 Package: src:squid; Maintainer for src:squid is Luigi Gangitano <luigi@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Fri, 5 Jul 2019 20:36:08 UTC Severity: important Tags: security, upstream Found in versions squid/46-1, squid/46-2 ...
Synopsis Moderate: squid:4 security and bug fix update Type/Severity Security Advisory: Moderate Topic An update for the squid:4 module is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring Syste ...
Synopsis Moderate: squid security and bug fix update Type/Severity Security Advisory: Moderate Topic An update for squid is now available for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring System (CVSS) base s ...
Several security issues were fixed in Squid ...
Several security issues were fixed in Squid ...
Several vulnerabilities were discovered in Squid, a fully featured web proxy cache The flaws in the HTTP Digest Authentication processing, the HTTP Basic Authentication processing and in the cachemgrcgi allowed remote attackers to perform denial of service and cross-site scripting attacks, and potentially the execution of arbitrary code For the ...
An issue was discovered in Squid before 502 A remote attacker can replay a sniffed Digest Authentication nonce to gain access to resources that are otherwise forbidden This occurs because the attacker can overflow the nonce reference counter (a short integer) Remote code execution may occur if the pooled token credentials are freed (instead of ...
An issue was discovered in Squid before 502 A remote attacker can replay a sniffed Digest Authentication nonce to gain access to resources that are otherwise forbidden This occurs because the attacker can overflow the nonce reference counter (a short integer) Remote code execution may occur if the pooled token credentials are freed (instead of ...
Impact: Moderate Public Date: 2019-07-05 Bugzilla: 1727744: CVe-2019-13345 squid: XSS via user_name or a ...