Description
mime_header.cc in Squid before 3.5.18 allows remote attackers to bypass intended same-origin restrictions and possibly conduct cache-poisoning attacks via a crafted HTTP Host header, aka a "header smuggling" issue.
Remediation
References
Related Vulnerabilities
phpMyFAQ Cleartext Transmission of Sensitive Information Vulnerability (CVE-2022-4409)
Oracle JRE CVE-2014-0459 Vulnerability (CVE-2014-0459)
WordPress Plugin user files Arbitrary File Upload (2.4.2)
Oracle HTTP Server Out-of-bounds Write Vulnerability (CVE-2022-23943)
Rukovoditel Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2021-30224)