Critical severity9.8NVD Advisory· Published Apr 15, 2020· Updated Jun 17, 2026
CVE-2019-12524
CVE-2019-12524
Description
An issue was discovered in Squid through 4.7. When handling requests from users, Squid checks its rules to see if the request should be denied. Squid by default comes with rules to block access to the Cache Manager, which serves detailed server information meant for the maintainer. This rule is implemented via url_regex. The handler for url_regex rules URL decodes an incoming request. This allows an attacker to encode their URL to bypass the url_regex check, and gain access to the blocked resource.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
24- Squid/Squiddescription
- osv-coords17 versionspkg:rpm/almalinux/libecappkg:rpm/almalinux/libecap-develpkg:rpm/suse/squid&distro=SUSE%20OpenStack%20Cloud%208pkg:rpm/suse/squid&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-BCLpkg:rpm/suse/squid&distro=HPE%20Helion%20OpenStack%208pkg:rpm/suse/squid&distro=SUSE%20OpenStack%20Cloud%207pkg:rpm/suse/squid&distro=SUSE%20OpenStack%20Cloud%20Crowbar%208pkg:rpm/suse/squid&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP2pkg:rpm/suse/squid&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP3pkg:rpm/suse/squid&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-LTSSpkg:rpm/suse/squid&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3-LTSSpkg:rpm/suse/squid&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3-BCLpkg:rpm/suse/squid&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP4pkg:rpm/suse/squid&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP4pkg:rpm/suse/squid&distro=SUSE%20Enterprise%20Storage%205pkg:rpm/suse/squid3&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4-LTSSpkg:rpm/suse/squid3&distro=SUSE%20Linux%20Enterprise%20Point%20of%20Sale%2011%20SP3
< 1.0.1-2.module_el8.6.0+2741+01592ae8+ 16 more
- (no CPE)range: < 1.0.1-2.module_el8.6.0+2741+01592ae8
- (no CPE)range: < 1.0.1-2.module_el8.6.0+2741+01592ae8
- (no CPE)range: < 3.5.21-26.23.1
- (no CPE)range: < 3.5.21-26.23.1
- (no CPE)range: < 3.5.21-26.23.1
- (no CPE)range: < 3.5.21-26.23.1
- (no CPE)range: < 3.5.21-26.23.1
- (no CPE)range: < 3.5.21-26.23.1
- (no CPE)range: < 3.5.21-26.23.1
- (no CPE)range: < 3.5.21-26.23.1
- (no CPE)range: < 3.5.21-26.23.1
- (no CPE)range: < 3.5.21-26.23.1
- (no CPE)range: < 3.5.21-26.23.1
- (no CPE)range: < 3.5.21-26.23.1
- (no CPE)range: < 3.5.21-26.23.1
- (no CPE)range: < 3.1.23-8.16.37.12.1
- (no CPE)range: < 3.1.23-8.16.37.12.1
cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*+ 1 more
- cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*
Patches
Vulnerability mechanics
References
5- gitlab.com/jeriko.one/security/-/blob/master/squid/CVEs/CVE-2019-12524.txtnvdThird Party Advisory
- lists.debian.org/debian-lts-announce/2020/07/msg00009.htmlnvdMailing ListThird Party Advisory
- security.netapp.com/advisory/ntap-20210205-0006/nvdThird Party Advisory
- usn.ubuntu.com/4446-1/nvdThird Party Advisory
- www.debian.org/security/2020/dsa-4682nvdThird Party Advisory
News mentions
0No linked articles in our index yet.