CVE-2019-13345

CVE-2019-13345

Published · Updated

25Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackepss 74%
exploitation probability
74%top 1% of all CVEs
observed exploitation
nono source reports it
What the vendors declare (VEX)

Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.

Affected
2 products (3 components)
Red Hat Enterprise Linux 6 · Red Hat Enterprise Linux 5
no_fix_planned: Out of support scope
Fixed
5 products (98 components)
Red Hat Enterprise Linux AppStream (v. 8) · Red Hat Enterprise Linux Server (v. 7) · Red Hat Enterprise Linux Server Optional (v. 7) · Red Hat Enterprise Linux Workstation (v. 7) · Red Hat Enterprise Linux Workstation Optional (v. 7)
The cachemgr.cgi web module of Squid through 4.7 has XSS via the user_name or auth parameter.
Affected products
n/a · n/a