Squid是Squid开源的一套代理服务器和Web缓存服务器软件。该软件提供缓存万维网、过滤流量、代理上网等功能。 Squid 7.2之前版本存在安全漏洞,该漏洞源于错误处理中未编辑HTTP身份验证凭据,可能导致信息泄露。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| squid-cache | squid | < 7.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | PoC of CVE-2025-62168 | https://github.com/monzaviman/CVE-2025-62168 | POC Details |
| 2 | PoC of CVE-2025-62168 | https://github.com/shahroodcert/CVE-2025-62168 | POC Details |
| 3 | Proof-of-Concept (PoC) for CVE-2025-62168 👾 | https://github.com/nehkark/CVE-2025-62168 | POC Details |
| 4 | Squid versions prior to 7.2 fail to redact HTTP authentication credentials in error page responses. The Authorization header value is embedded in plain text inside the mailto: diagnostic block when Squid generates an error page (e.g. ERR_DNS_FAIL). | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2025/CVE-2025-62168.yaml | POC Details |
No comments yet