Critical severity9.1NVD Advisory· Published Nov 26, 2019· Updated Jun 17, 2026
CVE-2019-12523
CVE-2019-12523
Description
An issue was discovered in Squid before 4.9. When handling a URN request, a corresponding HTTP request is made. This HTTP request doesn't go through the access checks that incoming HTTP requests go through. This causes all access checks to be bypassed and allows access to restricted HTTP servers, e.g., an attacker can connect to HTTP servers that only listen on localhost.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
39- Squid/Squiddescription
- osv-coords26 versionspkg:rpm/opensuse/squid&distro=openSUSE%20Tumbleweedpkg:rpm/almalinux/libecappkg:rpm/almalinux/libecap-develpkg:rpm/suse/squid&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5pkg:rpm/suse/squid&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP5pkg:rpm/suse/squid&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Server%20Applications%2015pkg:rpm/suse/squid&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Server%20Applications%2015%20SP1pkg:rpm/suse/squid&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-BCLpkg:rpm/opensuse/squid&distro=openSUSE%20Leap%2015.1pkg:rpm/suse/squid&distro=HPE%20Helion%20OpenStack%208pkg:rpm/suse/squid&distro=SUSE%20OpenStack%20Cloud%207pkg:rpm/suse/squid&distro=SUSE%20OpenStack%20Cloud%208pkg:rpm/suse/squid&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP2pkg:rpm/suse/squid&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-LTSSpkg:rpm/suse/squid&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3-LTSSpkg:rpm/suse/squid&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3-BCLpkg:rpm/suse/squid&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP4pkg:rpm/suse/squid&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP4pkg:rpm/suse/squid&distro=SUSE%20Enterprise%20Storage%205pkg:rpm/suse/squid3&distro=SUSE%20Linux%20Enterprise%20Point%20of%20Sale%2011%20SP3pkg:rpm/suse/squid&distro=SUSE%20OpenStack%20Cloud%20Crowbar%208pkg:rpm/suse/squid&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP3pkg:rpm/opensuse/squid&distro=openSUSE%20Leap%2015.0pkg:rpm/suse/squid3&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4-LTSSpkg:rpm/suse/squid&distro=SUSE%20Linux%20Enterprise%20Point%20of%20Sale%2011%20SP3pkg:rpm/suse/squid&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4-LTSS
< 4.16-1.5+ 25 more
- (no CPE)range: < 4.16-1.5
- (no CPE)range: < 1.0.1-2.module_el8.6.0+2741+01592ae8
- (no CPE)range: < 1.0.1-2.module_el8.6.0+2741+01592ae8
- (no CPE)range: < 4.9-4.3.2
- (no CPE)range: < 4.9-4.3.2
- (no CPE)range: < 4.9-5.11.1
- (no CPE)range: < 4.9-5.11.1
- (no CPE)range: < 3.5.21-26.20.1
- (no CPE)range: < 4.9-lp151.2.7.1
- (no CPE)range: < 3.5.21-26.20.1
- (no CPE)range: < 3.5.21-26.20.1
- (no CPE)range: < 3.5.21-26.20.1
- (no CPE)range: < 3.5.21-26.20.1
- (no CPE)range: < 3.5.21-26.20.1
- (no CPE)range: < 3.5.21-26.20.1
- (no CPE)range: < 3.5.21-26.20.1
- (no CPE)range: < 3.5.21-26.20.1
- (no CPE)range: < 3.5.21-26.20.1
- (no CPE)range: < 3.5.21-26.20.1
- (no CPE)range: < 3.1.23-8.16.37.12.1
- (no CPE)range: < 3.5.21-26.20.1
- (no CPE)range: < 3.5.21-26.20.1
- (no CPE)range: < 4.9-lp150.13.1
- (no CPE)range: < 3.1.23-8.16.37.12.1
- (no CPE)range: < 2.7.STABLE5-2.12.30.6.1
- (no CPE)range: < 2.7.STABLE5-2.12.30.6.1
cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*+ 4 more
- cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:19.04:*:*:*:*:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:19.10:*:*:*:*:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*
cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
9- www.squid-cache.org/Advisories/SQUID-2019_8.txtnvdThird Party Advisory
- bugzilla.suse.com/show_bug.cginvdIssue TrackingThird Party Advisory
- lists.debian.org/debian-lts-announce/2020/07/msg00009.htmlnvdMailing ListThird Party Advisory
- usn.ubuntu.com/4213-1/nvdThird Party Advisory
- usn.ubuntu.com/4446-1/nvdThird Party Advisory
- www.debian.org/security/2020/dsa-4682nvdThird Party Advisory
- lists.opensuse.org/opensuse-security-announce/2019-11/msg00056.htmlnvdBroken Link
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MTM74TU2BSLT5B3H4F3UDW53672NVLMC/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UEMOYTMCCFWK5NOXSXEIH5D2VGWVXR67/nvd
News mentions
0No linked articles in our index yet.