Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Squid 2.5, when processing the configuration file, parses empty Access Control Lists (ACLs), including proxy_auth ACLs without defined auth schemes, in a way that effectively removes arguments, which could allow remote attackers to bypass intended ACLs if the administrator ignores the parser warnings.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Squid 权限管理和访问控制漏洞
Vulnerability Description
Squid 2.5在处理配置文件时,采用一种有效删除参数的方式对空的访问控制列表(ACL)进行解析,其中包括不包含已定义验证方案的proxy_auth ACL,从而在如果管理员忽略解析器警告的情况下允许远程攻击者绕过设置的ACL。
CVSS Information
N/A
Vulnerability Type
N/A