CVE-2020-8449 is a high-severity vulnerability in Squid versions prior to 4.10, affecting various Linux distributions and the Squid caching proxy itself. It allows attackers to bypass security filters and access prohibited server resources due to incorrect input validation in crafted HTTP requests. The vulnerability has a CVSS score of 7.5, indicating a network-exploitable flaw with low attack complexity and high confidentiality impact, but no integrity or availability impact. While no public exploits, Metasploit modules, or KEV entries exist, and there's minimal community discussion or media coverage, organizations using affected Squid versions should patch promptly.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.10CPE matchmatch criteria | cpe:2.3:a:squid-cache:squid:*:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* | ||
16.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:* | ||
18.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.