Squid 2.2.STABLE5 and below, when using external authentication, allows attackers to bypass access controls via a newline in the user/password pair.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Squid_web_proxy | National_science_foundation | 1.0 | 1.0 |
Squid_web_proxy | National_science_foundation | 1.0novm | 1.0novm |
Squid_web_proxy | National_science_foundation | 1.1 | 1.1 |
Squid_web_proxy | National_science_foundation | 2.1 | 2.1 |
Squid_web_proxy | National_science_foundation | 2.2 | 2.2 |