CVE-2001-1030

5 documents5 sources
Severity
7.5HIGH
EPSS
0.2%
top 59.90%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 18
Latest updateApr 30

Description

Squid before 2.3STABLE5 in HTTP accelerator mode does not enable access control lists (ACLs) when the httpd_accel_host and http_accel_with_proxy off settings are used, which allows attackers to bypass the ACLs and conduct unauthorized activities such as port scanning.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages8 packages

NVDsquid/squid_web_proxy2.3stable3, 2.3stable4+1
NVDredhat/linux7.0
NVDimmunix/immunix6.2, 7.0, 7.0_beta+2
NVDtrustix/secure_linux1.01, 1.1, 1.2+2

Patches

🔴Vulnerability Details

2
GHSA
GHSA-g8hh-whpr-gfp2: Squid before 22022-04-30
CVEList
CVE-2001-1030: Squid before 22002-06-25

📋Vendor Advisories

1
Red Hat
security flaw2001-07-18

💬Community

1
Bugzilla
CVE-2001-1030 security flaw2018-08-16