Cross-site scripting in Squid - CVE-2019-13345

 

Cross-site scripting in Squid - CVE-2019-13345

Published: July 11, 2019 / Updated: July 15, 2019


Vulnerability identifier: #VU19140
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: CVE-2019-13345
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.

The vulnerability exists due to insufficient sanitization of user-supplied data passed via the  the "user_name" and "auth" parameters to the cachemgr.cgi web module. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website.

Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.

Example:

http://[host]/cgi-bin/cachemgr.cgi?host=localhost&port=3128&user_name=admin&operation=authenticate&auth=bG9jYWxob3N0fDE1NTg5NTYzNzJ8YWRtIj48c2NyaXB0PmFsZXJ0KCdYU1MnKTwvc2NyaXB0PmlufGRzZGFkYWE=


Affected software

Squid
Amazon Linux AMI
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux Server
Anolis OS
Red Hat Enterprise Linux for x86_64
Opensuse
Fedora
squid3 (Ubuntu package)
squid (Red Hat package)
squid (Alpine package)
squid (Debian package)
squid
squid-migration-script
squid-sysvinit

How to mitigate CVE-2019-13345

Install update from vendor's website.

Squid - update to 4.8
squid3 (Ubuntu package) - update to 3.1.19-1ubuntu3.12.04.9
squid (Red Hat package) - update to 3.5.20-15.el7
squid (Alpine package) - addressed in versions 3.5.27-r1, 3.5.27-r3
squid (Debian package) - update to 4.6-1+deb10u1
squid - update to 3.5.20-17
squid-migration-script - update to 3.5.20-17
squid-sysvinit - update to 3.5.20-17
squid - addressed in versions 4.4-2.fc29, 4.8-1.fc29, 4.8-1.fc30, 4.8-2.fc29

External References

Related Security Bulletins