Description
Squid 3.2.x before 3.2.14, 3.3.x before 3.3.14, 3.4.x before 3.4.13, and 3.5.x before 3.5.4, when configured with client-first SSL-bump, do not properly validate the domain or hostname fields of X.509 certificates, which allows man-in-the-middle attackers to spoof SSL servers via a valid certificate.
Remediation
References
Related Vulnerabilities
Ruby on Rails URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2023-22797)
WordPress Plugin WP Content Copy Protection & No Right Click Cross-Site Request Forgery (3.1.5)
Django Incorrect Default Permissions Vulnerability (CVE-2020-24583)
WordPress Missing Authentication for Critical Function Vulnerability (CVE-2020-11028)
Joomla Improper Input Validation Vulnerability (CVE-2016-8870)