SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-18677

An issue was discovered in Squid 3.x and 4.x through 4.8 when the append_domain setting is used (because the appended characters do not properly interact with hostname length restrictions).

MEDIUM 6.1EPSS 7.24%

Does this matter?

Lower severity and a low EPSS score (7.24%). Track it; it rarely justifies an emergency change on its own.

Description

An issue was discovered in Squid 3.x and 4.x through 4.8 when the append_domain setting is used (because the appended characters do not properly interact with hostname length restrictions). Due to incorrect message processing, it can inappropriately redirect traffic to origins it should not be delivered to.

CVSS 3.1
6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS
7.24% probability · 94th percentile
CISA KEV
Not listed
Weakness
CWE-352
Affected
squid-cache/squid · canonical/ubuntu linux · fedoraproject/fedora
Source
cve@mitre.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.