Ukuba sesichengeni kwiseva engummeli yeSquid ekuvumela ukuba ugqithe kwizithintelo zofikelelo

Ityhiliwe ulwazi malunga nobuthathaka kwiseva engummeli Isikwati, ezathi cwaka kunyaka ophelileyo ekukhutshweni kweSquid 4.8. Iingxaki zikhona kwikhowudi yokucwangcisa "@" ibhloko ekuqaleni kwe-URL ("umsebenzisi @ inginginya") kwaye ikuvumela ukuba ugqithe kwimithetho yothintelo lofikelelo, ityhefu imixholo yecache, kwaye uphumeze indawo enqamlezileyo. uhlaselo lombhalo.

  • I-CVE-2019-12524 β€” umxhasi, esebenzisa i-URL eyilwe ngokukodwa, unokugqitha kwimigaqo ekhankanyiweyo esebenzisa i-url_regex yomyalelo kwaye afumane ulwazi oluyimfihlo malunga ne-proxy kunye ne-traffic ecwangcisiweyo (ukufumana ukufikelela kwi-interface yoMphathi weCache).
  • I-CVE-2019-12520 -ngokusebenzisa idatha yegama lomsebenzisi kwi-URL, unokufezekisa ukugcinwa komxholo ongeyonyani wephepha elithile kwi-cache, ethi, umzekelo, ingasetyenziselwa ukucwangcisa ukwenziwa kwekhowudi yakho yeJavaScript kumxholo wezinye iisayithi.

umthombo: opennet.ru

Yongeza izimvo