peter bassill · operator
$ cve CVE-2019-12523 JSON

CVE-2019-12523

9.1
CRITICAL · CVSS 3.1 · EPSS 4.3% (pctl 91)

In your normal cycle

Critical by CVSS (9.1), but no sign of active exploitation.

Description

An issue was discovered in Squid before 4.9. When handling a URN request, a corresponding HTTP request is made. This HTTP request doesn't go through the access checks that incoming HTTP requests go through. This causes all access checks to be bypassed and allows access to restricted HTTP servers, e.g., an attacker can connect to HTTP servers that only listen on localhost.

Scoring

CVSS9.1 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
EPSS4.3% — more likely to be exploited than 91% of all CVEs
On CISA KEVno
Public exploitnone known
Published2019-11-26
Last modified2026-06-17

Affected (5)

VendorProduct
canonicalubuntu linux
debiandebian linux
fedoraprojectfedora
opensuseleap
squid-cachesquid

References

→ the Explorer  ·  watch your stack  ·  NVD