Vulnerability Name: | CVE-2021-33620 (CCN-202715) | ||||||||||||||||||||||||||||||||||||||||
Assigned: | 2021-05-10 | ||||||||||||||||||||||||||||||||||||||||
Published: | 2021-05-10 | ||||||||||||||||||||||||||||||||||||||||
Updated: | 2022-06-03 | ||||||||||||||||||||||||||||||||||||||||
Summary: | Squid before 4.15 and 5.x before 5.0.6 allows remote servers to cause a denial of service (affecting availability to all clients) via an HTTP response. The issue trigger is a header that can be expected to exist in HTTP traffic without any malicious intent by the server. | ||||||||||||||||||||||||||||||||||||||||
CVSS v3 Severity: | 6.5 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H) 5.7 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
5.7 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
5.7 Medium (REDHAT Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
| ||||||||||||||||||||||||||||||||||||||||
CVSS v2 Severity: | 4.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:S/C:N/I:N/A:P)
| ||||||||||||||||||||||||||||||||||||||||
Vulnerability Type: | CWE-20 | ||||||||||||||||||||||||||||||||||||||||
Vulnerability Consequences: | Denial of Service | ||||||||||||||||||||||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2021-33620 Source: MISC Type: Mailing List, Patch, Vendor Advisory http://www.squid-cache.org/Versions/v4/changesets/squid-4-1e05a85bd28c22c9ca5d3ac9f5e86d6269ec0a8c.patch Source: MISC Type: Mailing List, Patch, Vendor Advisory http://www.squid-cache.org/Versions/v5/changesets/squid-5-8af775ed98bfd610f9ce762fe177e01b2675588c.patch Source: XF Type: UNKNOWN squidcache-cve202133620-dos(202715) Source: CCN Type: SQUID-2021:5 Denial of Service in HTTP Response processing Source: MISC Type: Patch, Third Party Advisory https://github.com/squid-cache/squid/security/advisories/GHSA-572g-rvwr-6c7f Source: MLIST Type: Mailing List, Third Party Advisory [debian-lts-announce] 20210614 [SECURITY] [DLA 2685-1] squid3 security update Source: FEDORA Type: Third Party Advisory FEDORA-2021-c0bec55ec7 Source: FEDORA Type: Third Party Advisory FEDORA-2021-24af72ff2c Source: CCN Type: WhiteSource Vulnerability Database CVE-2021-33620 | ||||||||||||||||||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration 3: Configuration RedHat 1: Configuration RedHat 2: Configuration CCN 1: ![]() | ||||||||||||||||||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||||||||
BACK |