CVE-2021-33620
Public on 2021-05-28
Modified on 2024-07-11
Description
Squid before 4.15 and 5.x before 5.0.6 allows remote servers to cause a denial of service (affecting availability to all clients) via an HTTP response. The issue trigger is a header that can be expected to exist in HTTP traffic without any malicious intent by the server.
Severity
See what this means
CVSS v3 Base Score
See breakdown
Affected Packages
Platform | Package | Release Date | Advisory | Status |
---|---|---|---|---|
Amazon Linux 1 | squid | 2023-02-22 | ALAS-2023-1687 | Fixed |
Amazon Linux 2 - Core | squid | 2023-02-21 | ALAS2-2023-1950 | Fixed |
Amazon Linux 2 - Squid4 Extra | squid | 2023-09-25 | ALAS2SQUID4-2023-004 | Fixed |
Amazon Linux 2023 | squid | Not Affected |
CVSS Scores
Score Type | Score | Vector | |
---|---|---|---|
Amazon Linux | CVSSv3 | 6.5 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
NVD | CVSSv2 | 4.0 | AV:N/AC:L/Au:S/C:N/I:N/A:P |
NVD | CVSSv3 | 6.5 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |