


Community Manager
Options
- Subscribe to RSS Feed
- Mark as New
- Mark as Read
- Bookmark
- Subscribe
- Printer Friendly Page
- Report Inappropriate Content
11-27-2023
11:37 AM
Summary
Squid has discovered an issue where it checks its cache for response availability by making an MD5 hash of the absolute URL. This can include decoded UserInfo, allowing attackers to provide a username with special characters and treat the rest of the URL as a path or query string. This could lead to access to features only reverse proxies can use.
Products Potentially Affected
OS/Product | Exposure |
IQ Engine (HiveOS) | Yes |
Repair Recommendations
- IQ Engine (HiveOS): Pending.
Please see the full security advisory article here for more details and updates.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.