Vulnerability Description
SQUID is vulnerable to HTTP request smuggling, caused by chunked decoder lenience, allows a remote attacker to perform Request/Response smuggling past firewall and frontend security systems.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Squid-Cache | Squid | >= 2.6, < 6.4 |
| Redhat | Enterprise Linux | 8.0 |
| Redhat | Enterprise Linux Eus | 8.6 |
| Redhat | Enterprise Linux For Arm 64 | 8.0_aarch64 |
| Redhat | Enterprise Linux For Ibm Z Systems | 8.0_s390x |
| Redhat | Enterprise Linux For Power Little Endian | 8.0_ppc64le |
| Redhat | Enterprise Linux Server Aus | 8.2 |
| Redhat | Enterprise Linux Server Tus | 8.2 |
Related Weaknesses (CWE)
References
- https://access.redhat.com/errata/RHSA-2023:6266Third Party Advisory
- https://access.redhat.com/errata/RHSA-2023:6267Third Party Advisory
- https://access.redhat.com/errata/RHSA-2023:6268Third Party Advisory
- https://access.redhat.com/errata/RHSA-2023:6748Third Party Advisory
- https://access.redhat.com/errata/RHSA-2023:6801Third Party Advisory
- https://access.redhat.com/errata/RHSA-2023:6803Third Party Advisory
- https://access.redhat.com/errata/RHSA-2023:6804Third Party Advisory
- https://access.redhat.com/errata/RHSA-2023:6810Third Party Advisory
- https://access.redhat.com/errata/RHSA-2023:7213Third Party Advisory
- https://access.redhat.com/errata/RHSA-2024:11049
- https://access.redhat.com/security/cve/CVE-2023-46846Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2245910Issue TrackingThird Party Advisory
- https://github.com/squid-cache/squid/security/advisories/GHSA-j83v-w3p4-5cqhVendor Advisory
- https://access.redhat.com/errata/RHSA-2023:6266Third Party Advisory
- https://access.redhat.com/errata/RHSA-2023:6267Third Party Advisory
FAQ
What is CVE-2023-46846?
CVE-2023-46846 is a vulnerability with a CVSS score of 9.3 (CRITICAL). SQUID is vulnerable to HTTP request smuggling, caused by chunked decoder lenience, allows a remote attacker to perform Request/Response smuggling past firewall and frontend security systems.
How severe is CVE-2023-46846?
CVE-2023-46846 has been rated CRITICAL with a CVSS base score of 9.3/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2023-46846?
Check the references section above for vendor advisories and patch information. Affected products include: Squid-Cache Squid, Redhat Enterprise Linux, Redhat Enterprise Linux Eus, Redhat Enterprise Linux For Arm 64, Redhat Enterprise Linux For Ibm Z Systems.