VDB

CVE-2015-5400

CVE-2015-5400 PUBLISHED

Squid before 3.5.6 does not properly handle CONNECT method peer responses when configured with cache_peer, which allows remote attackers to bypass intended restrictions and gain access to a backend proxy via a CONNECT request.

EPSS 24.70% · 96.2th percentile

Risk Scores

EPSS Score
24.70%
96.2th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSsquid33.3.8-1ubuntu16, 3.3.8-1ubuntu17, 0

Timeline

  • Sep 28, 2015 CVE Published
  • Feb 4, 2022 EPSS Score
  • Dec 17, 2024 EPSS Score
  • Mar 17, 2025 EPSS Score
  • Mar 21, 2025 EPSS Score
  • Mar 22, 2025 EPSS Score
  • Mar 25, 2025 EPSS Score
  • Mar 29, 2025 EPSS Score
  • Mar 30, 2025 EPSS Score
  • Apr 3, 2025 EPSS Score
  • Apr 7, 2025 EPSS Score
  • May 1, 2025 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›