CVE Vulnerabilities

CVE-2015-5400

Published: Sep 28, 2015 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
2.3 LOW
AV:A/AC:M/Au:S/C:P/I:N/A:N
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

Squid before 3.5.6 does not properly handle CONNECT method peer responses when configured with cache_peer, which allows remote attackers to bypass intended restrictions and gain access to a backend proxy via a CONNECT request.

Affected Software

NameVendorStart VersionEnd Version
FedoraFedoraproject22 (including)22 (including)
Squid3Ubuntudevel*
Squid3Ubuntuesm-infra/xenial*
Squid3Ubuntuprecise*
Squid3Ubuntutrusty*
Squid3Ubuntuupstream*
Squid3Ubuntuutopic*
Squid3Ubuntuvivid*
Squid3Ubuntuwily*
Squid3Ubuntuxenial*

References