Lucene search

K
redhatcveRedhat.comRH:CVE-2023-50269
HistoryDec 15, 2023 - 5:28 a.m.

CVE-2023-50269

2023-12-1505:28:57
redhat.com
access.redhat.com
18
squid
uncontrolled recursion
remote dos
http request parsing
x-forwarded-for
denial of service
configuration
mitigation

8.6 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

0.005 Low

EPSS

Percentile

75.3%

A flaw was found in Squid, which is susceptible to a Denial of Service (DoS) due to an Uncontrolled Recursion bug, specifically targeting HTTP Request parsing. Exploiting this issue involves a remote client initiating a DoS attack by sending an oversized X-Forwarded-For header when the follow_x_forwarded_for feature is configured. This issue poses a threat to the stability and availability of the Squid service.

Mitigation

Remove all "follow_x_forwarded_for" lines from squid.conf.

8.6 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

0.005 Low

EPSS

Percentile

75.3%