Squid is a caching proxy for the Web. In Squid versions prior to 7.2, a failure to redact HTTP authentication credentials in error handling allows information disclosure. The vulnerability allows a script to bypass browser security protections and learn the credentials a trusted client uses to authenticate. This potentially allows a remote client to identify security tokens or credentials used internally by a web application using Squid for backend load balancing. These attacks do not require Squid to be configured with HTTP authentication. The vulnerability is fixed in version 7.2. As a workaround, disable debug information in administrator mailto links generated by Squid by configuring squid.conf with email_err_data off.
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2025:19107 https://access.redhat.com/errata/RHSA-2025:19107
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions Via RHSA-2025:19114 https://access.redhat.com/errata/RHSA-2025:19114
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions Via RHSA-2025:19118 https://access.redhat.com/errata/RHSA-2025:19118
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Extended Update Support Via RHSA-2025:19115 https://access.redhat.com/errata/RHSA-2025:19115
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Extended Lifecycle Support Via RHSA-2025:19167 https://access.redhat.com/errata/RHSA-2025:19167
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions Red Hat Enterprise Linux 8.6 Telecommunications Update Service Via RHSA-2025:19277 https://access.redhat.com/errata/RHSA-2025:19277
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions Red Hat Enterprise Linux 8.8 Telecommunications Update Service Via RHSA-2025:19398 https://access.redhat.com/errata/RHSA-2025:19398
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.2 Advanced Update Support Via RHSA-2025:19967 https://access.redhat.com/errata/RHSA-2025:19967
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2025:20935 https://access.redhat.com/errata/RHSA-2025:20935
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2025:21002 https://access.redhat.com/errata/RHSA-2025:21002
This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2025:21065 https://access.redhat.com/errata/RHSA-2025:21065
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2025:21066 https://access.redhat.com/errata/RHSA-2025:21066
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On Via RHSA-2025:21090 https://access.redhat.com/errata/RHSA-2025:21090