« Volver al listado

CVE-2012-2213

Estado: ModificadaMedia (5)—

Squid 3.1.9 allows remote attackers to bypass the access configuration for the CONNECT method by providing an arbitrary allowed hostname in the Host HTTP header. NOTE: this issue might not be reproducible, because the researcher is unable to provide a squid.conf file for a vulnerable system, and the observed behavior is consistent with a squid.conf file that was (perhaps inadvertently) designed to allow access based on a "req_header Host" acl regex that matches www.uol.com.br

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2012-2213",
  "cveTags": [
    {
      "tags": [
        "disputed"
      ],
      "sourceIdentifier": "cve@mitre.org"
    }
  ],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2012-04-28T10:06:13.273",
  "references": [
    {
      "url": "http://archives.neohapsis.com/archives/bugtraq/2012-04/0117.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://archives.neohapsis.com/archives/bugtraq/2012-04/0131.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://archives.neohapsis.com/archives/bugtraq/2012-04/0140.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://archives.neohapsis.com/archives/bugtraq/2012-04/0146.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://archives.neohapsis.com/archives/bugtraq/2012-04/0163.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://archives.neohapsis.com/archives/bugtraq/2012-04/0165.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://archives.neohapsis.com/archives/bugtraq/2012-04/0117.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://archives.neohapsis.com/archives/bugtraq/2012-04/0131.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://archives.neohapsis.com/archives/bugtraq/2012-04/0140.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://archives.neohapsis.com/archives/bugtraq/2012-04/0146.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://archives.neohapsis.com/archives/bugtraq/2012-04/0163.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://archives.neohapsis.com/archives/bugtraq/2012-04/0165.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-264"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Squid 3.1.9 allows remote attackers to bypass the access configuration for the CONNECT method by providing an arbitrary allowed hostname in the Host HTTP header.  NOTE: this issue might not be reproducible, because the researcher is unable to provide a squid.conf file for a vulnerable system, and the observed behavior is consistent with a squid.conf file that was (perhaps inadvertently) designed to allow access based on a \"req_header Host\" acl regex that matches www.uol.com.br"
    },
    {
      "lang": "es",
      "value": "** EN DISPUTA ** Squid v3.1.9 permite a atacantes remotos evitar la configuración de acceso para el método CONNECT, proporcionando un nombre de host arbitrario en la cabecera 'host HTTP'. NOTA: este problema no puede ser reproducible, porque el investigador es incapaz de proporcionar un archivo squid.conf de un sistema vulnerable, y el comportamiento observado es consistente con un archivo squid.conf que fue (tal vez sin darse cuenta), diseñado para permitir el acceso basado en una expresión regular de ACL \"host req_header\" que coincide con www.uol.com.br."
    }
  ],
  "lastModified": "2026-06-16T23:41:11.623",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:squid-cache:squid:3.1.9:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "41914354-D5BE-4B1F-BED3-0ECA43586537"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}