SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2024-45802

Due to Input Validation, Premature Release of Resource During Expected Lifetime, and Missing Release of Resource after Effective Lifetime bugs, Squid is vulnerable to Denial of Service attacks by a trusted server against all clients using the proxy.

HIGH 7.5EPSS 47.9%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 47.9%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.

Description

Squid is an open source caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to Input Validation, Premature Release of Resource During Expected Lifetime, and Missing Release of Resource after Effective Lifetime bugs, Squid is vulnerable to Denial of Service attacks by a trusted server against all clients using the proxy. This bug is fixed in the default build configuration of Squid version 6.10.

CVSS 3.1
7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS
47.88% probability · 99th percentile
CISA KEV
Not listed
Weakness
CWE-20
Affected
squid-cache/squid
Source
security-advisories@github.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.