VDB

CVE-2021-41611

CVE-2021-41611 PUBLISHED CVSS 7.5 HIGH

An issue was discovered in Squid 5.0.6 through 5.1.x before 5.2. When validating an origin server or peer certificate, Squid may incorrectly classify certain certificates as trusted. This problem allows a remote server to obtain security trust well improperly. This indication of trust may be passed along to clients, allowing access to unsafe or hijacked services.

EPSS 2.95% · 86.2th percentile

Risk Scores

CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score
2.95%
86.2th percentile

Affected Products

VendorProductVersions
fedoraprojectfedora35
squid-cachesquid5.0.6
n/an/an/a

Timeline

  • Oct 18, 2021 CVE Published
  • Oct 19, 2021 EPSS Score
  • Dec 14, 2021 EPSS Score
  • Feb 4, 2022 EPSS Score
  • Feb 9, 2022 EPSS Score
  • Apr 6, 2022 EPSS Score
  • Jun 2, 2022 EPSS Score
  • Sep 23, 2022 EPSS Score
  • Nov 19, 2022 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Mar 12, 2023 EPSS Score
  • May 7, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›