Logo
vulnerabilityCVE-2025-62168
Name
CVE-2025-62168
Source
NVD ( link)Debian ( link)
Description
Squid is a caching proxy for the Web. In Squid versions prior to 7.2, a failure to redact HTTP authentication credentials in error handling allows information disclosure. The vulnerability allows a script to bypass browser security protections and learn the credentials a trusted client uses to authenticate. This potentially allows a remote client to identify security tokens or credentials used internally by a web application using Squid for backend load balancing. These attacks do not require Squid to be configured with HTTP authentication. The vulnerability is fixed in version 7.2. As a workaround, disable debug information in administrator mailto links generated by Squid by configuring squid.conf with email_err_data off.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
squid
Exploitable

Vulnerability Ratings#


10
CVSSv31
7.5
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
6.14
Patched
buildroot
master
7.6
Not Affected
openwrt
master
7.1-r1
Exploitable
openwrt
openwrt-25.12
7.1-r1
Exploitable
yocto
master
7.5
Not Affected
yocto
scarthgap
6.14
Exploitable

Resolved with patches#


squid (buildroot:2025.02.x)

#
Title
Author
Resolve
1
Bug 3390: Proxy auth data visible to scripts (#2249)
Amos Jeffries <yadij@users.noreply.github.com>
CVE-2025-62168