Description
An issue was discovered in http/ContentLengthInterpreter.cc in Squid before 4.12 and 5.x before 5.0.3. A Request Smuggling and Poisoning attack can succeed against the HTTP cache. The client sends an HTTP request with a Content-Length header containing "+\ "-" or an uncommon shell whitespace character prefix to the length field-value.
Remediation
References
Related Vulnerabilities
WordPress Plugin WP-Live Chat by 3CX Multiple Vulnerabilities (4.3.5)
Seo Panel Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2024-22643)
WordPress Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2017-6514)
WordPress Plugin Gwolle Guestbook Multiple Vulnerabilities (2.1.0)