TROYANOSYVIRUS
Back to CVEs

CVE-2024-45802

HIGH
7.5

Description

Squid is an open source caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to Input Validation, Premature Release of Resource During Expected Lifetime, and Missing Release of Resource after Effective Lifetime bugs, Squid is vulnerable to Denial of Service attacks by a trusted server against all clients using the proxy. This bug is fixed in the default build configuration of Squid version 6.10.

CVE Details

CVSS v3.1 Score7.5
SeverityHIGH
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack VectorNETWORK
ComplexityLOW
Privileges RequiredNONE
User InteractionNONE
Published10/28/2024
Last Modified11/3/2025
Sourcenvd
Honeypot Sightings0

Affected Products

squid-cache:squid

Weaknesses (CWE)

CWE-20

IOC Correlations

No correlations recorded

This product uses data from the NVD API but is not endorsed or certified by the NVD.