Vulnerability in the Squid proxy server that allows bypassing access restrictions
Details about vulnerabilities in the Squid proxy server have been revealed, which were discreetly addressed last year in the Squid 4.8 release. Issues exist in the code handling the "@" block at the beginning of the URL ("user@host") and allow for circumventing access restriction rules, spoofing cache content, and performing cross-site scripting attacks. CVE-2019-12524 — a client can exploit this with a specially formatted […]
