Cross-site scripting in Squid - CVE-2019-13345
Published: July 11, 2019 / Updated: July 15, 2019
Vulnerability details
The vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data passed via the the "user_name" and "auth" parameters to the cachemgr.cgi web module. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website.
Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.
Example:
http://[host]/cgi-bin/cachemgr.cgi?host=localhost&port=3128&user_name=admin&operation=authenticate&auth=bG9jYWxob3N0fDE1NTg5NTYzNzJ8YWRtIj48c2NyaXB0PmFsZXJ0KCdYU1MnKTwvc2NyaXB0PmlufGRzZGFkYWE=
Affected software
Amazon Linux AMI
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux Server
Anolis OS
Red Hat Enterprise Linux for x86_64
Opensuse
Fedora
squid3 (Ubuntu package)
squid (Red Hat package)
squid (Alpine package)
squid (Debian package)
squid
squid-migration-script
squid-sysvinit
How to mitigate CVE-2019-13345
squid3 (Ubuntu package) - update to 3.1.19-1ubuntu3.12.04.9
squid (Red Hat package) - update to 3.5.20-15.el7
squid (Alpine package) - addressed in versions 3.5.27-r1, 3.5.27-r3
squid (Debian package) - update to 4.6-1+deb10u1
squid - update to 3.5.20-17
squid-migration-script - update to 3.5.20-17
squid-sysvinit - update to 3.5.20-17
squid - addressed in versions 4.4-2.fc29, 4.8-1.fc29, 4.8-1.fc30, 4.8-2.fc29
External References
Related Security Bulletins
- Multiple vulnerabilities in Squid
- Ubuntu update for Squid
- OpenSUSE Linux update for squid
- Debian update for squid
- Red Hat update for squid:4
- OpenSUSE Linux update for squid
- OpenSUSE Linux update for squid
- Red Hat Enterprise Linux 7 update for squid
- Amazon Linux AMI update for squid
- Cross-site scripting in squid (Alpine package)
- Anolis OS update for squid
- Fedora 29 update for squid
- Fedora 30 update for squid
- Fedora 29 update for squid
- Fedora 29 update for squid