CVE-2020-8449

HIGH

Squid <4.10 - SSRF

Title source: llm

Description

An issue was discovered in Squid before 4.10. Due to incorrect input validation, it can interpret crafted HTTP requests in unexpected ways to access server resources prohibited by earlier security filters.

References (15)

Scores

CVSS v3 7.5
EPSS 0.0352
EPSS Percentile 87.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Classification

CWE
CWE-668
Status published

Affected Products (9)

squid-cache/squid < 4.10
debian/debian_linux
debian/debian_linux
canonical/ubuntu_linux
canonical/ubuntu_linux
canonical/ubuntu_linux
opensuse/leap
fedoraproject/fedora
fedoraproject/fedora

Timeline

Published Feb 04, 2020
Tracked Since Feb 18, 2026