Chiwopsezo mu seva ya proxy ya Squid yomwe imakupatsani mwayi wolambalala zoletsa

Zawululidwa zambiri zokhudzana ndi zovuta mu seva ya proxy Sikwidi, zomwe zinathetsedwa mwakachetechete chaka chatha pakutulutsidwa kwa Squid 4.8. Mavuto alipo mu code yokonza chipika cha "@" kumayambiriro kwa ulalo ("user@host") ndikukulolani kuti mulambalale malamulo oletsa kulowa, kuwononga zomwe zili mu cache, ndikuyika malo ochezera. scripting attack.

  • CVE-2019-12524 - kasitomala, pogwiritsa ntchito ulalo wopangidwa mwapadera, amatha kulambalala malamulo omwe afotokozedwa pogwiritsa ntchito url_regex malangizo ndikupeza zinsinsi za proxy ndi magalimoto osinthidwa (kupezani mawonekedwe a Cache Manager).
  • CVE-2019-12520 - pogwiritsa ntchito dzina lolowera mu ulalo, mutha kukwaniritsa zopeka patsamba linalake mu cache, zomwe, mwachitsanzo, zitha kugwiritsidwa ntchito kukonza ma code anu a JavaScript malinga ndi masamba ena.

Source: opennet.ru

Kuwonjezera ndemanga