Kusagadzikana muSquid proxy server iyo inokutendera kuti upfuure zvirambidzo zvekuwana

Zvakazarurwa ruzivo rwekusagadzikana muproxy server Squid, iyo yakabviswa chinyararire gore rapfuura mukuburitswa kweSquid 4.8. Matambudziko aripo mukodhi yekugadzirisa iyo "@" block pakutanga kweURL ("mushandisi @ host") uye inobvumidza iwe kudarika mitemo yekudzivirira yekupinda, chepfu zviri mukati mecache, uye kuita nzvimbo yekuyambuka. scripting attack.

  • CVE-2019-12524 - mutengi, achishandisa URL yakanyatsogadzirwa, anogona kunzvenga mitemo yakataurwa uchishandisa url_regex rairo uye kuwana ruzivo rwekuvanzika nezve proxy uye yakagadziriswa traffic (kuwana mukana weCache Manager interface).
  • CVE-2019-12520 - nekushandisa dhizaini data muURL, unogona kuwana kuchengetwa kwezvinhu zvenhema zveimwe peji mune cache, iyo, semuenzaniso, inogona kushandiswa kuronga kuitiswa kweJavaScript kodhi yako mumamiriro emamwe masaiti.

Source: opennet.ru

Voeg