VDB

CVE-2021-41611

CVE-2021-41611 PUBLISHED CVSS 7.5 HIGH

An issue was discovered in Squid 5.0.6 through 5.1.x before 5.2. When validating an origin server or peer certificate, Squid may incorrectly classify certain certificates as trusted. This problem allows a remote server to obtain security trust well improperly. This indication of trust may be passed along to clients, allowing access to unsafe or hijacked services.

EPSS 1.12% · 78.5th percentile

Risk Scores

CVSS v3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score
1.12%
78.5th percentile

Affected Products

VendorProductVersions
fedoraprojectfedora35
squid-cachesquid5.0.6
n/an/an/a

Timeline

  • Oct 18, 2021 CVE Published
  • Oct 19, 2021 EPSS Score
  • Dec 14, 2021 EPSS Score
  • Feb 4, 2022 EPSS Score
  • Feb 8, 2022 EPSS Score
  • Apr 6, 2022 EPSS Score
  • Jun 1, 2022 EPSS Score
  • Jul 28, 2022 EPSS Score
  • Nov 18, 2022 EPSS Score
  • Jan 13, 2023 EPSS Score
  • Mar 10, 2023 EPSS Score
  • May 5, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›