Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-47905

Опубликовано: 13 мая 2025
Источник: debian
EPSS Низкий

Описание

Varnish Cache before 7.6.3 and 7.7 before 7.7.1, and Varnish Enterprise before 6.0.13r14, allow client-side desync via HTTP/1 requests, because the product incorrectly permits CRLF to be skipped to delimit chunk boundaries.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
varnishfixed7.7.0-2package

Примечания

  • https://varnish-cache.org/security/VSV00016.html

  • https://github.com/varnishcache/varnish-cache/commit/b5f1faba6e8d9848cfe0cba566986e7e5cc5f65b (varnish-7.7.1)

  • https://github.com/varnishcache/varnish-cache/commit/13904252859cf9848db5999b08c42d83a03ed812 (varnish-7.7.1)

  • https://github.com/varnishcache/varnish-cache/commit/3d9a9abff1c6734feea9d48d5852ccad7e7d0a42 (varnish-7.7.1)

  • https://github.com/varnishcache/varnish-cache/commit/00cb14931a53efafbdfec9843453fb1347bc9f59 (varnish-7.7.1)

EPSS

Процентиль: 18%
0.00058
Низкий

Связанные уязвимости

CVSS3: 5.4
ubuntu
около 1 месяца назад

Varnish Cache before 7.6.3 and 7.7 before 7.7.1, and Varnish Enterprise before 6.0.13r14, allow client-side desync via HTTP/1 requests, because the product incorrectly permits CRLF to be skipped to delimit chunk boundaries.

CVSS3: 8.1
redhat
около 1 месяца назад

Varnish Cache before 7.6.3 and 7.7 before 7.7.1, and Varnish Enterprise before 6.0.13r14, allow client-side desync via HTTP/1 requests, because the product incorrectly permits CRLF to be skipped to delimit chunk boundaries.

CVSS3: 5.4
nvd
около 1 месяца назад

Varnish Cache before 7.6.3 and 7.7 before 7.7.1, and Varnish Enterprise before 6.0.13r14, allow client-side desync via HTTP/1 requests, because the product incorrectly permits CRLF to be skipped to delimit chunk boundaries.

CVSS3: 5.4
github
около 1 месяца назад

Varnish Cache before 7.6.3 and 7.7 before 7.7.1, and Varnish Enterprise before 6.0.13r14, allow client-side desync via HTTP/1 requests, because the product incorrectly permits CRLF to be skipped to delimit chunk boundaries.

oracle-oval
17 дней назад

ELSA-2025-8337: varnish security update (IMPORTANT)

EPSS

Процентиль: 18%
0.00058
Низкий