The latest high-severity Citrix vulnerability under attack isn’t easy to fix

Enraged computer technician man screaming and breaking a PC with a hammer.
Getty Images

A critical vulnerability that hackers have exploited since August, which allows them to bypass multifactor authentication in Citrix networking hardware, has received a patch from the manufacturer. Unfortunately, applying it isn’t enough to protect affected systems.

The vulnerability, tracked as CVE-2023-4966 and carrying a severity rating of 9.8 out of a possible 10, resides in the NetScaler Application Delivery Controller and NetScaler Gateway, which provide load balancing and single sign-on in enterprise networks, respectively. Stemming from a flaw in a currently unknown function, the information-disclosure vulnerability can be exploited so hackers can intercept encrypted communications passing between devices. The vulnerability can be exploited remotely and with no human action required, even when attackers have no system privileges on a vulnerable system.

Citrix released a patch for the vulnerability last week, along with an advisory that provided few details. On Wednesday, researchers from security firm Mandiant said that the vulnerability has been under active exploitation since August, possibly for espionage against professional services, technology, and government organizations. Mandiant warned that patching the vulnerability wasn’t sufficient to lock down affected networks because any sessions hijacked before the security update would persist afterward.

The company wrote:

Successful exploitation could result in the ability to hijack existing authenticated sessions, therefore bypassing multi factor authentication or other strong authentication requirements. These sessions may persist after the update to mitigate CVE-2023-4966 has been deployed. Additionally, we have observed session hijacking where session data was stolen prior to the patch deployment, and subsequently used by a threat actor.

The authenticated session hijacking could then result in further downstream access based upon the permissions and scope of access that the identity or session was permitted. A threat actor could utilize this method to harvest additional credentials, laterally pivot, and gain access to additional resources within an environment.

Mandiant provided security guidance that goes well beyond the advice Citrix provided. Specifically:

• Isolate NetScaler ADC and Gateway appliances for testing and preparation of patch deployment.

Note: If the vulnerable appliances cannot be prioritized for patching, Mandiant recommends that the appliances have ingress IP address restrictions enforced to limit the exposure and attack surface until the necessary patches have been applied.

• Upgrade vulnerable NetScaler ADC and Gateway appliances to the latest firmware versions, which mitigate the vulnerability.

• Post upgrading, terminate all active and persistent sessions (per appliance).

– Connect to the NetScaler appliance using the CLI.

• To terminate all active sessions, run the following command: kill aaa session -all

• To clear persistent sessions across NetScaler load balancers, run the following command (where is the name of the virtual server / appliance): clear lb persistentSessions

• To clear existing ICA sessions, run the following command: kill icaconnection -all

• Credential Rotation

– Due to the lack of available log records or other artifacts of exploitation activity, as a precaution, organizations should consider rotating credentials for identities that were provisioned for accessing resources via a vulnerable NetScaler ADC or Gateway appliance.

– If there is evidence of suspicious activity or lateral movement within an environment, organizations should prioritize credential rotation for a larger scope of identities if single factor authentication (SFA) remote access is allowed for any resources from the Internet.

• If web shells or backdoors are identified on NetScaler appliances, Mandiant recommends rebuilding the appliances using a clean-source image, including the latest firmware.

Note: If a restoration of an appliance is required using a backup image, the backup configuration should be reviewed to ensure that there is no evidence of backdoors.

• If possible, reduce the external attack exposure and attack surface of NetScaler appliances by restricting ingress access to only trusted or predefined source IP address ranges.

The advice is warranted given the track record from previous exploitation of critical Citrix vulnerabilities. For example, Citrix disclosed and released a patch for a separate 9.8 vulnerability on July 18. Three days later, according to Internet scans by security organization Shadowserver, more than 18,000 instances had yet to apply the critical update.

By then, according to the US Cybersecurity and Infrastructure Security Administration, the vulnerability was already under active exploit. In the subsequent weeks,  Shadowserver and security firms F-Secure and IBM Security Intelligence tracked thousands of exploitations used for credential theft.

What Mandiant’s guidance amounts to is this: If your organization uses either NetScaler ADC or NetScaler Gateway that’s on-premises, you should assume it has been hacked and follow the guidance provided. And yes, that includes patching first.

https://arstechnica.com/?p=1977305




Number of Cisco Devices Hacked via Unpatched Vulnerability Increases to 40,000

The number of Cisco devices hacked through the exploitation of an unpatched IOS XE vulnerability has reached approximately 40,000, according to multiple cybersecurity firms. 

The exploited vulnerability is CVE-2023-20198, a critical flaw affecting the IOS XE web interface that can be exploited by remote, unauthenticated attackers for privilege escalation. 

Cisco has yet to release patches and the company warned that the vulnerability has been exploited as a zero-day since at least mid-September.

CVE-2023-20198 allows threat actors to create high-privileged accounts on targeted devices and take complete control of the system. In some cases, attackers have been observed delivering an implant that enables them to execute arbitrary commands. 

Cisco said in some cases the implants were delivered via an older flaw tracked as CVE-2021-1435, but a previously unknown vulnerability may have also been exploited because the implant was also spotted on systems patched against CVE-2021-1435.

Vulnerability intelligence company VulnCheck conducted an internet scan shortly after the zero-day’s existence came to light and found 10,000 compromised switches and routers, but noted that the number would likely increase as its scanning had been ongoing.  

While VulnCheck has yet to provide an update, a scan conducted by the internet search engine Censys on October 17 showed 67,000 internet-exposed IOS XE web interfaces, including more than 34,000 hosts that appeared to have been backdoored. Another scan conducted by Censys the next day showed that the number of hacked systems increased to nearly 42,000.

Advertisement. Scroll to continue reading.

A majority of the compromised Cisco devices appear to be in the United States, followed by the Philippines and Latin America. India, Thailand, Singapore and Australia also have a significant number of infections.

LeakIX, which scans the internet for vulnerable systems, initially reported seeing the malicious implant on roughly 30,000 Cisco devices, but its latest scan detected an additional 10,000 compromised systems.

Threat intelligence company GreyNoise has been using its honeypots to track attack attempts and as of October 19 it has seen attacks originating from 230 unique IP addresses.   

Related: Cisco Warns of IOS Software Zero-Day Exploitation Attempts

Related: Cisco ASA Zero-Day Exploited in Akira Ransomware Attacks

https://www.securityweek.com/number-of-cisco-devices-hacked-via-unpatched-vulnerability-increases-to-40000/




Three Months After Patch, Gov-Backed Actors Exploiting WinRAR Flaw

Malware hunters in Google’s Threat Analysis Group (TAG) say government-backed hacking groups from different countries are feasting on a well-documented security flaw in the popular WinRAR file archiving utility more than three months after patches were released.

The WinRAR code execution vulnerability, tracked as CVE-2023-38831, was fixed in July after zero-day exploitation was detected but now, three months later, Google says APT groups linked to Russia and China are still using the exploit with success.

“Cybercrime groups began exploiting the vulnerability in early 2023, when the bug was still unknown to defenders. A patch is now available, but many users still seem to be vulnerable,” Google’s Kate Morgan said in a note documenting the APT discoveries. “After a vulnerability has been patched, malicious actors will continue to rely on n-days and use slow patching rates to their advantage.”

Morgan said the flaw, which allows attackers to execute arbitrary code when a user attempts to view a benign file (such as an ordinary PNG file) within a ZIP archive, has been known since at least April 2023 and immediately attracted the interest of threat actors.

“Hours after the blog post [about zero-day exploitation] was released, proof of concepts and exploit generators were uploaded to public GitHub repositories. Shortly after that, TAG began to observe testing activity from both financially motivated and APT actors experimenting with CVE-2023-38831,” Morgan added.

In one case, Google TAG detected the Russia-linked Sandworm delivering decoy PDF documents and malicious ZIP files exploiting the WinRAR bug.  Sandworm, aligned with Russian Armed Forces’ Main Directorate of the General Staff (GRU) Unit, used the exploit to deliver a commodity infostealer that is able to collect and exfiltrate browser credentials and session information from infected machines. 

Morgan documented another incident where APT28, another hacking team linked to Russian GRU, used a free hosting provider to serve CVE-2023-38831 to target users in Ukraine. 

Advertisement. Scroll to continue reading.

Google said it also caught government-backed groups linked to China launching WinRAR exploits in targeted attacks against users in Papua New Guinea.

“The widespread exploitation of the WinRAR bug highlights that exploits for known vulnerabilities can be highly effective, despite a patch being available. Even the most sophisticated attackers will only do what is necessary to accomplish their goals,” Morgan warned.

Software security defects in the WinRAR tool are constantly being targeted by cybercriminals and APT groups.  SecurityWeek has reported on multiple WinRAR exploitation incidents recently, including usage by financially motivated hackers against traders and .gov-backed advanced threat actors.

Related: Traders Targeted by Cybercriminals in Attack Exploiting WinRAR Zero-Day

Related: WinRAR Vulnerability Exploited to Deliver New Malware

Related: Recently Patched WinRAR Flaw Exploited in APT Attacks

Related: Hackers Exploit WinRAR Vulnerability to Deliver Malware

https://www.securityweek.com/three-months-after-patch-gov-backed-actors-exploiting-winrar-flaw/




US Gov Expects Widespread Exploitation of Atlassian Confluence Vulnerability

US cybersecurity agency CISA, the FBI, and the Multi-State Information Sharing and Analysis Center (MS-ISAC) warn organizations of potential widespread exploitation of a recent zero-day vulnerability in Atlassian Confluence Data Center and Server.

Tracked as CVE-2023-22515 (CVSS score of 9.8), the bug has been exploited by a nation-state threat actor since September 14, roughly two weeks before Atlassian released patches for it.

Remotely exploitable without authentication, the flaw is described as a broken access control issue leading to privilege escalation. The issue impacts on-premises Confluence instances only.

“This recently disclosed vulnerability affects certain versions of Atlassian Confluence Data Center and Server, enabling malicious cyber threat actors to obtain initial access to Confluence instances by creating unauthorized Confluence administrator accounts,” CISA, FBI, and MS-ISAC note in an advisory (PDF).

Because it allows threat actors to modify critical configuration settings, the flaw may be used for more malicious actions than the creation of administrative accounts, the advisory reads. 

“Threat actors can change the Confluence server’s configuration to indicate the setup is not complete and use the /setup/setupadministrator.action endpoint to create a new administrator user. The vulnerability is triggered via a request on the unauthenticated /server-info.action endpoint,” the three agencies say.

CISA added CVE-2023-22515 to its Known Exploited Vulnerabilities catalog on October 5 and warns that, following the publication of proof-of-concept (PoC) exploit code, multiple threat actors have started targeting the flaw in attacks.

Advertisement. Scroll to continue reading.

“Due to the ease of exploitation, CISA, FBI, and MS-ISAC expect to see widespread exploitation of unpatched Confluence instances in government and private networks,” the advisory continues.

The vulnerability impacts Confluence Data Center and Server versions 8.0.0 to 8.5.1 and has been addressed with the release of versions 8.3.3, 8.4.3, and 8.5.2 of the product.

Organizations with internet-accessible Confluence Data Center and Server instances are advised to update to a patched release as soon as possible. They should also consider restricting network access until the updates are applied.

In their advisory, CISA, FBI, and MS-ISAC have included details on the exploitation of CVE-2023-22515, as well as indicators-of-compromise (IoCs) to help organizations hunt for malicious activity associated with the bug’s exploitation.

“CISA, FBI, and MS-ISAC strongly encourage network administrators to immediately apply the upgrades provided by Atlassian. CISA, FBI, and MS-ISAC also encourage organizations to hunt for malicious activity on their networks using the detection signatures and indicators of compromise (IOCs),” the US gov agencies note.

Related: Atlassian Security Updates Patch High-Severity Vulnerabilities

Related: Organizations Warned of Critical Confluence Flaw as Exploitation Continues

Related: Atlassian Patches Remote Code Execution Vulnerabilities in Confluence, Bamboo

https://www.securityweek.com/us-gov-expects-widespread-exploitation-of-atlassian-confluence-vulnerability/




Cisco Devices Hacked via IOS XE Zero-Day Vulnerability

Cisco is warning customers that a new zero-day vulnerability impacting the company’s IOS XE software is being exploited to hack devices.

The critical vulnerability is tracked as CVE-2023-20198 and it has been described as a privilege escalation issue impacting the IOS XE web user interface, which comes with the default image. A remote, unauthenticated attacker can exploit the vulnerability to create an account that has the highest privileges — level 15 access — and use it to take control of the device.

“With this level of access, an attacker can modify network routing rules as well as open ports for access to attacker controlled servers for data exfiltration,” warned Scott Caveza, staff research engineer at Tenable. “When the attacker has this level of control and makes an administrative account with an innocuous name, it’s possible their activity could go undetected for quite some time.”

The vulnerability can be exploited from the network or directly from the internet if the targeted device is exposed to the web.

In a blog post published on Monday, Cisco’s Talos unit revealed that the company became aware of attacks exploiting CVE-2023-20198 on September 28, when its Technical Assistance Center (TAC) investigated unusual behavior on a customer’s device. 

Further analysis showed that the malicious activity, which involved the creation of a new user account named ‘cisco_tac_admin’, started as early as September 18. 

This activity appeared to end on October 1, but Cisco again started seeing malicious activity — presumably conducted by the same threat actor — on October 12. 

Advertisement. Scroll to continue reading.

While the September activity did not involve other actions beyond the creation of a new account, in October the hackers also deployed an implant. This implant, consisting of a configuration file, allows the attacker to execute arbitrary commands at system or IOS level. 

For interaction with the implant, a new web server endpoint needs to be created, and the implant is only activated if this web server is restarted, which did not happen in all cases observed by Cisco.

The threat actor delivered the implant by exploiting CVE-2021-1435, an IOS XE command injection vulnerability patched by Cisco in March 2021. However, the company has also seen the implant being installed on devices patched against CVE-2021-1435 and the delivery mechanism in this case remains unknown for the time being.

The networking giant also noted that the implant is not persistent — it’s removed when the device is rebooted — but the accounts created by the attackers remain even after the system has been restarted. 

“Both [activity] clusters appeared close together, with the October activity appearing to build off the September activity. The first cluster was possibly the actor’s initial attempt and testing their code, while the October activity seems to show the actor expanding their operation to include establishing persistent access via deployment of the implant,” Cisco said.

The company’s blog post does not say who may be behind these attacks.

Cisco is working on a patch for CVE-2023-20198. Until it becomes available, the vendor recommends that customers disable the HTTP Server feature on their internet-facing systems. The company has also shared a list of indicators of compromise (IoCs) that organizations can use to check whether their devices have been hacked.

The US cybersecurity agency CISA has added CVE-2023-20198 to its Known Exploited Vulnerabilities Catalog, instructing government organizations to deploy mitigations by October 20.

Related: Cisco Warns of IOS Software Zero-Day Exploitation Attempts

Related: Cisco ASA Zero-Day Exploited in Akira Ransomware Attacks

https://www.securityweek.com/cisco-devices-hacked-via-ios-xe-zero-day-vulnerability/




WordPress Websites Hacked via Royal Elementor Plugin Zero-Day

Security researchers are warning of a critical-severity vulnerability in the Royal Elementor Addons and Templates WordPress plugin that has been exploited as a zero-day for more than a month.

Developed by WP Royal, the plugin helps domain admins build their websites without any coding experience. Royal Elementor has more than 200,000 active installations on the WordPress marketplace.

The exploited bug, tracked as CVE-2023-5360 (CVSS score of 9.8), is described as an insufficient file type validation in the plugin’s upload function, allowing unauthenticated attackers to upload arbitrary files to vulnerable sites, leading to remote code execution.

The flaw impacts all Royal Elementor versions prior to 1.3.79 and, according to WordPress security firm Defiant, has been exploited in malicious attacks since at least August 30.

To date, the security firm has seen more than 46,000 attacks attempting to exploit this vulnerability, with an increase in activity observed on October 3.

Most attacks, Defiant says, came from three different IP addresses and were aimed at deploying specific files on the target sites, to create a malicious administrator account.

According to Automattic’s WPScan team, which identified and reported the vulnerability, the attackers were seen deploying at least one malicious file into the /wpr-addons/forms/ directory.

Advertisement. Scroll to continue reading.

The plugin, Automattic explains, relied on a simple extension validation to ensure that only certain file types could be uploaded, but which allowed unauthenticated users to manipulate the list of allowed extensions.

“Upon investigation we found that wp_unique_filename WordPress function performs file name and extensions sanitization and, when combined with the file_validity function, would enable bad actors to manipulate the input and bypass the checks,” Automattic notes.

Site admins should check the /wpr-addons/forms/ directory for the presence of malicious PHP files, including one file creating a user account named ‘wordpress_administrator’.

Automattic also observed that threat actors have been exploiting the vulnerability to upload malware to the compromised websites.

Administrators and site owners are advised to update to Royal Elementor version 1.3.79, which patches the vulnerability. The patched version has been available since October 6.

Related: Backdoor Malware Found on WordPress Website Disguised as Legitimate Plugin

Related: Recently Patched TagDiv Plugin Flaw Exploited to Hack Thousands of WordPress Sites

Related: Vulnerability in WordPress Migration Plugin Exposes Websites to Attacks

https://www.securityweek.com/wordpress-websites-hacked-via-royal-elementor-plugin-zero-day/




Signal Pours Cold Water on Zero-Day Exploit Rumors

Privacy-focused messaging firm Signal is pouring cold water on widespread rumors of a zero-day exploit in its popular encrypted chat app.

“We have seen the vague viral reports alleging a Signal 0-day vulnerability. After responsible investigation *we have no evidence that suggests this vulnerability is real* nor has any additional info been shared via our official reporting channels,” Signal said late Sunday night.

Rumors of a Signal zero-day started circulating over the weekend with what appears to be a copy-pasted warning the “generate link preview” feature could be exploited to take full control of devices.

“To close the vulnerability, have everyone go to settings under your profile in signal> chats> deselect “generate link preview”. Also make sure your signal app is up to date,” according to the cryptic note.

The original source for the zero-day warning is unknown but Signal said it checked with its contacts across the US Government, since the copy-paste report claimed USG as a source.  “Those we spoke to have no info suggesting this is a valid claim,” the company said on X, the social media site previously known as Twitter.

The “generate link preview” feature is known to have privacy and security risks and has led to critical-severity vulnerability problems on Meta’s WhatsApp platform. 

The feature, on by default on some Signal installations, displays a short summary and preview image of a URL being sent but experts have long warned that it provides attack surface to leak IP addresses, expose links sent in end-to-end encrypted chats, and unnecessarily downloading gigabytes of data quietly in the background.

Advertisement. Scroll to continue reading.

Interestingly, Apple’s optional LockDown Mode disables the iMessage link preview feature in response to malicious targeting by surveillance spyware vendors.

Related: Link Previews in Chat Apps Pose Privacy, Security Issues

Related: Signal Discloses Impact From Twilio Hack

Related: Vulnerability in WhatsApp Desktop Exposed User Files

Related: Can ‘Lockdown Mode’ Solve Apple’s Mercenary Spyware Problem?

https://www.securityweek.com/signal-pours-cold-water-on-zero-day-exploit-rumors/




CISA Now Flagging Vulnerabilities, Misconfigurations Exploited by Ransomware

The US cybersecurity agency CISA is stepping up its efforts to prevent ransomware by making it easier for organizations to learn about vulnerabilities and misconfigurations exploited in these attacks.

As part of its Ransomware Vulnerability Warning Pilot (RVWP) program launched in March, the agency has released two new resources to help organizations identify and eliminate security flaws and weaknesses known to be exploited by ransomware groups.

“Through the RVWP, CISA determines vulnerabilities that are commonly associated with known ransomware exploitation and warns critical infrastructure entities with those vulnerabilities, helping to enable mitigation before a ransomware incident occurs,” CISA notes.

The first of these resources is a new column in the Known Exploited Vulnerabilities catalog, which flags flaws that CISA is aware of being associated with ransomware campaigns.

The catalog lists more than 1,000 vulnerabilities for which CISA has solid evidence of in-the-wild exploitation, many of which have been targeted in ransomware attacks.

One of the most recent examples of such flaws is CVE-2023-40044, a deserialization of untrusted data bug in Progress Software’s WS_FTP server that could lead to the execution of remote commands on the underlying operating system.

The other new resource CISA is offering now is a new table on the StopRansomware project’s website, which lists information on the misconfigurations and weaknesses that ransomware operators have been observed targeting in their attacks.

Advertisement. Scroll to continue reading.

For each issue, the table also provides information on the Cyber Performance Goal (CPG) actions that organizations can take as part of their mitigation or compensation efforts.

“These two new resources will help organizations become more cybersecure by providing mitigations that protect against specific KEVs, misconfigurations, and weaknesses associated with ransomware,” CISA notes.

According to CISA, its RVWP has identified more than 800 vulnerable systems to date, within the networks of organizations in the energy, education facilities, healthcare and public health, and water systems industries.

“Ransomware has disrupted critical services, businesses, and communities worldwide and many of these incidents are perpetrated by ransomware actors using known common vulnerabilities and exposures. However, many organizations may be unaware that a vulnerability used by ransomware threat actors is present on their network,” CISA notes.

The agency encourages all organizations to take action to reduce the risk of ransomware by reviewing the available resources. Critical infrastructure entities are encouraged to enroll in CISA’s vulnerability scanning service to receive targeted notifications.

Related: US Government Releases Security Guidance for Open Source Software in OT, ICS

Related: CISA Warns of Attacks Exploiting Adobe Acrobat Vulnerability

Related: Organizations Warned of Top 10 Cybersecurity Misconfigurations Seen by CISA, NSA

https://www.securityweek.com/cisa-now-flagging-vulnerabilities-misconfigurations-exploited-by-ransomware/




Juniper Networks Patches Over 30 Vulnerabilities in Junos OS

Networking equipment manufacturer Juniper Networks on Thursday announced patches for more than 30 vulnerabilities in Junos OS and Junos OS Evolved, including nine high-severity flaws.

The most severe of these issues is an incorrect default permissions bug that allows an unauthenticated attacker with local access to a vulnerable device to create a backdoor with root privileges.

Tracked as CVE-2023-44194 (CVSS score of 8.4), the flaw exists because a certain system directory has improper permissions associated with it.

Juniper’s patches also address six high-severity vulnerabilities in Junos OS and Junos OS Evolved that could lead to denial of service (DoS). Five of these can be exploited remotely, without authentication.

Impacting both Junos OS and Junos OS Evolved, the remaining two high-severity issues can be exploited to impact the stability of devices and the confidentiality and integrity of device operations, respectively.

All the remaining flaws resolved with this week’s Junos OS and Junos OS Evolved updates are medium-severity vulnerabilities that could lead to DoS conditions, bypass of intended access restrictions, impact on the integrity of systems or connected networks, impact on system availability, credentials leak, configuration changes leak, DMA memory leak, or the incorrect forwarding of MAC addresses.

Additionally, Juniper released patches for a series of medium-severity vulnerabilities in third-party software used within Junos OS and Junos OS Evolved, including NTP vulnerabilities and cryptographic algorithm issues.

Advertisement. Scroll to continue reading.

The networking products maker has released software updates that address these vulnerabilities for Junos OS and Junos OS Evolved versions 20.4, 21.1, 21.2, 21.3, 21.4, 22.1, 22.2, 22.3, 22.4, 23.1, 23.2, and 23.3.

Juniper Networks says it is not aware of any of these vulnerabilities being exploited in malicious attacks.

Users are advised to apply the available patches as soon as possible, given that vulnerabilities in networking products, including Juniper devices, are known to have been exploited in the wild.

Additional information can be found on Juniper’s support portal.

Related: Thousands of Juniper Appliances Vulnerable to New Exploit

Related: Recent Juniper Flaws Chained in Attacks Following PoC Exploit Publication

Related: Juniper Networks Patches High-Severity Vulnerabilities in Junos OS

https://www.securityweek.com/juniper-networks-patches-over-30-vulnerabilities-in-junos-os/




Dozens of Squid Proxy Vulnerabilities Remain Unpatched 2 Years After Disclosure

Dozens of vulnerabilities affecting the Squid caching and forwarding web proxy remain unpatched two years after a researcher responsibly disclosed them to developers.

Squid is a widely used open source proxy. According to the official site, “Many of you are using Squid without even knowing it! Some companies have embedded Squid in their home or office firewall devices, others use Squid in large-scale web proxy installations to speed up broadband and dialup internet access. Squid is being increasingly used in content delivery architectures to deliver static and streaming video/audio to internet users worldwide.”

The Squid security holes were discovered in 2021 by researcher Joshua Rogers, who this week disclosed the technical details of his findings. Rogers identified 55 vulnerabilities by targeting various components with fuzzing, manual code review and static analysis. 

According to the researcher, only a handful of flaws have been assigned CVE identifiers and 35 of them remain unpatched. 

Many of the vulnerabilities can lead to a crash, but some can also be exploited for arbitrary code execution.

“The Squid Team have been helpful and supportive during the process of reporting these issues. However, they are effectively understaffed, and simply do not have the resources to fix the discovered issues. Hammering them with demands to fix the issues won’t get far,” Rogers said.

The researcher pointed out that there are more than 2.5 million Squid instances exposed on the internet.

Advertisement. Scroll to continue reading.

“With any system or project, it is important to regularly review solutions used in your stack to determine whether they are still appropriate,” the researcher said. “If you are running Squid in an environment which may suffer from any of these issues, then it is up to you to reassess whether Squid is the right solution for your system.”

SecurityWeek has reached out to Squid developers for comment and will update this article if they respond. 

Related: Top 10 Security, Operational Risks From Open Source Code

Related: SBOMs – Software Supply Chain Security’s Future or Fantasy?

Related: GitLab Security Update Patches Critical Vulnerability

https://www.securityweek.com/dozens-of-squid-proxy-vulnerabilities-remain-unpatched-2-years-after-disclosure/