The Vigil@nce team watches public vulnerabilities impacting your computers, and then offers security solutions, a database and tools to fix them.

vulnerability bulletin CVE-2018-19131 CVE-2018-19132

Squid cache: Cross Site Scripting via TLS Errors

Synthesis of the vulnerability

An attacker can trigger a Cross Site Scripting via TLS Errors of Squid cache, in order to run JavaScript code in the context of the web site.
Impacted products: Squid, SUSE Linux Enterprise Desktop, SLES.
Severity: 2/4.
Creation date: 29/10/2018.
Identifiers: CERTFR-2018-AVI-518, CVE-2018-19131, CVE-2018-19132, SQUID-2018:4, SUSE-SU-2018:3771-1, SUSE-SU-2018:3786-1, SUSE-SU-2018:3790-1, VIGILANCE-VUL-27633.

Description of the vulnerability

The Squid cache product offers a web service. However, it does not filter rec...
Complete Vigil@nce bulletin.... (Free trial)

Computer vulnerabilities tracking service

Vigil@nce provides a software vulnerabilities alert. The Vigil@nce vulnerability database contains several thousand vulnerabilities. The Vigil@nce team tracks computer vulnerabilities impacting systems and applications. The technology watch team tracks security threats targeting the computer system.