CVE-2019-12520 is a high-severity vulnerability in Squid versions through 4.7 and 5, affecting various Canonical and Debian Linux distributions running Squid. It allows an attacker to manipulate Squid's cache by crafting a URL with a specially encoded username, leading to the serving of malicious content instead of legitimate responses. The vulnerability has a CVSS score of 7.5, indicating a high impact on confidentiality with low attack complexity and no user interaction required. While no public exploit code or active exploitation has been observed, and community discussion is minimal, organizations using affected Squid versions should apply available patches to mitigate this risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 4.7CPE matchmatch criteria | cpe:2.3:a:squid-cache:squid:*:*:*:*:*:*:*:* | ||
16.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:* | ||
18.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.