Improper access control in Squid - CVE-2022-41317

 

Improper access control in Squid - CVE-2022-41317

Published: September 23, 2022


Vulnerability identifier: #VU67604
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-41317
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to gain access to sensitive information.

The vulnerability exists due to inconsistent handling of internal URIs. A remote authenticated proxy user can bypass the manager ACL protection and access cache manager information, which includes records of internal network structure, client credentials, client identity and client traffic behavior.


Affected software

Squid
Amazon Linux AMI
Debian Linux
SUSE CaaS Platform
SUSE Manager Proxy
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Enterprise Storage
SUSE Linux Enterprise Storage
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Server Applications
SUSE Linux Enterprise Server for SAP Applications
openSUSE Leap
Ubuntu
openEuler
Fedora
squid
squid-debugsource
squid-debuginfo
squid (Ubuntu package)
squid (Debian package)

How to mitigate CVE-2022-41317

Install updates from vendor's website.

Squid - update to 5.7
squid - update to 3.5.20-17.44
squid-debugsource - addressed in versions 3.5.21-26.38.1, 4.17-4.27.1, 4.17-150000.5.35.1, 5.7-150400.3.6.1
squid-debuginfo - addressed in versions 3.5.21-26.38.1, 4.17-4.27.1, 4.17-150000.5.35.1, 5.7-150400.3.6.1
squid - addressed in versions 3.5.21-26.38.1, 4.17-4.27.1, 4.17-150000.5.35.1, 5.7-150400.3.6.1
squid (Ubuntu package) - addressed in versions 3.5.27-1ubuntu1.14, 4.10-1ubuntu1.7, 5.2-1ubuntu4.2
squid-debuginfo - update to 4.9-13
squid-debugsource - update to 4.9-13
squid - update to 4.9-13
squid (Debian package) - update to 4.13-10+deb11u2
squid - addressed in versions 5.7-1.fc35, 5.7-1.fc36, 5.7-1.fc37

External References

Related Security Bulletins