CVE-2020-8449: Input Validation
An issue was discovered in Squid before 4.10. Due to incorrect input validation, it can interpret crafted HTTP requests in unexpected ways to access server resources prohibited by earlier security filters.
Other sources
Squid could allow a remote attacker to obtain sensitive information, caused by improper input validation. By sending a specially-crafted HTTP request, an attacker could exploit this vulnerability to obtain server resources information, and use this information to launch further attacks against the affected system.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2020-8449?
CVE-2020-8449 is a vulnerability in Squid that allows a remote attacker to obtain sensitive information.
What is the severity of CVE-2020-8449?
CVE-2020-8449 has a severity rating of 7.5 (High).
How does CVE-2020-8449 work?
CVE-2020-8449 exploits improper input validation in Squid by sending a specially-crafted HTTP request to obtain server resources information.
Which versions of Squid are affected by CVE-2020-8449?
Squid versions before 4.10 are affected by CVE-2020-8449.
How can I fix CVE-2020-8449?
To fix CVE-2020-8449, update Squid to version 4.10 or later.