Rashin lahani a cikin uwar garken wakili na Squid wanda ke ba ku damar ketare ƙuntatawa shiga

Ya bayyana bayani game da lahani a cikin uwar garken wakili squid, wanda aka kawar da shiru a bara a cikin sakin Squid 4.8. Matsalolin suna nan a cikin lambar don sarrafa toshe "@" a farkon URL ("mai amfani @ mai watsa shiri") kuma yana ba ku damar ketare ka'idojin ƙuntatawa, lalata abubuwan da ke cikin cache, da aiwatar da hanyar ketare. harin rubutun.

  • CVE-2019-12524 - abokin ciniki, ta amfani da URL ɗin da aka ƙera na musamman, na iya ƙetare ƙa'idodin da aka kayyade ta amfani da umarnin url_regex kuma ya sami bayanan sirri game da wakili da zirga-zirgar da aka sarrafa (samun damar yin amfani da mu'amalar Cache Manager).
  • CVE-2019-12520 - ta hanyar sarrafa bayanan sunan mai amfani a cikin URL, zaku iya cimma ma'ajin tatsuniyoyi don takamaiman shafi a cikin cache, wanda, alal misali, ana iya amfani da shi don tsara aiwatar da lambar JavaScript ɗinku a cikin mahallin sauran rukunin yanar gizon.

source: budenet.ru

Add a comment