Ukuba sengozini kuseva elibamba le-Squid elikuvumela ukuthi udlule imikhawulo yokufinyelela

Kwembulwa ulwazi olumayelana nokuba sengozini kuseva elibamba Squid, eyaqedwa buthule ngonyaka odlule ekukhishweni kwe-squid 4.8. Izinkinga zikhona kukhodi yokucubungula ibhulokhi ethi β€œ@” ekuqaleni kwe-URL (β€œuser@host”) futhi ikuvumela ukuthi weqe imithetho yemikhawulo yokufinyelela, ushevu okuqukethwe kunqolobane, futhi wenze indawo enqamulayo. scripting attack.

  • I-CVE-2019-12524 β€” iklayenti, lisebenzisa i-URL eklanywe ngokukhethekile, lingakwazi ukweqa imithetho eshiwo kusetshenziswa umyalo we-url_regex futhi lithole ulwazi oluyimfihlo mayelana nommeleli kanye nethrafikhi ecutshunguliwe (lithole ukufinyelela kusixhumi esibonakalayo Somphathi Wenqolobane).
  • I-CVE-2019-12520 β€” ngokukhohlisa idatha yegama lomsebenzisi ku-URL, ungafinyelela ukugcinwa kokuqukethwe okungelona iqiniso ekhasini elithile kunqolobane, isibonelo, okungasetshenziswa ukuhlela ukusetshenziswa kwekhodi yakho ye-JavaScript kumongo wamanye amasayithi.

Source: opennet.ru

Engeza amazwana