Aller au contenu

Fiche vulnérabilité

CVE-2021-41611 : faille élevée squid-cache squid (CVSS 7.5)

Description

An issue was discovered in Squid 5.0.6 through 5.1.x before 5.2. When validating an origin server or peer certificate, Squid may incorrectly classify certain certificates as trusted. This problem allows a remote server to obtain security trust well improperly. This indication of trust may be passed along to clients, allowing access to unsafe or hijacked services.

En bref

Sévérité
Élevée (CVSS 7.5)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitation active
Non signalée par la CISA
Publication
18 oct. 2021
Dernière mise à jour
17 juin 2026

Produits concernés

  • squid-cache squid
  • fedoraproject fedora

Références

Rechercher une autre vulnérabilité dans la base CVE