An issue was discovered in Squid 5.0.6 through 5.1.x before 5.2. When validating an origin server or peer certificate, Squid may incorrectly classify certain certificates as trusted. This problem allows a remote server to obtain security trust well improperly. This indication of trust may be passed along to clients, allowing access to unsafe or hijacked services.
| Software | From | Fixed in |
|---|---|---|
| squid-cache / squid | 5.0.6 | 5.2 |
| fedoraproject / fedora | 35 | 35.x |