#VU67604 Improper access control in Squid - CVE-2022-41317
Published: September 23, 2022
Squid
Squid-cache.org
Description
The vulnerability allows a remote user to gain access to sensitive information.
The vulnerability exists due to inconsistent handling of internal URIs. A remote authenticated proxy user can bypass the manager ACL protection and access cache manager information, which includes records of internal network structure, client credentials, client identity and client traffic behavior.