Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-23959

Опубликовано: 25 янв. 2022
Источник: redhat
CVSS3: 9.1
EPSS Низкий

Описание

In Varnish Cache before 6.6.2 and 7.x before 7.0.2, Varnish Cache 6.0 LTS before 6.0.10, and and Varnish Enterprise (Cache Plus) 4.1.x before 4.1.11r6 and 6.0.x before 6.0.9r4, request smuggling can occur for HTTP/1 connections.

A flaw was found in Varnish. This flaw allows an attacker to carry out a request smuggling attack on HTTP/1 connections on Varnish cache servers. This smuggled request goes through the usual Varnish Configuration Language (VCL) processing since the Varnish server treats it as an additional request.

Меры по смягчению последствий

This issue can be mitigated by ensuring that the Varnish server does not allow connection reuse on HTTP/1 client connections once a request body has been seen on the connection. This requires changes in the VCL configuration.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 9varnishNot affected
Red Hat Enterprise Linux 8varnishFixedRHSA-2022:041803.02.2022
Red Hat Enterprise Linux 8.1 Update Services for SAP SolutionsvarnishFixedRHSA-2022:042003.02.2022
Red Hat Enterprise Linux 8.2 Extended Update SupportvarnishFixedRHSA-2022:042103.02.2022
Red Hat Enterprise Linux 8.4 Extended Update SupportvarnishFixedRHSA-2022:042203.02.2022
Red Hat Software Collections for Red Hat Enterprise Linux 7rh-varnish6-varnishFixedRHSA-2022:474525.05.2022

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-444
https://bugzilla.redhat.com/show_bug.cgi?id=2045031varnish: HTTP/1 request smuggling vulnerability

EPSS

Процентиль: 57%
0.00346
Низкий

9.1 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.1
ubuntu
около 4 лет назад

In Varnish Cache before 6.6.2 and 7.x before 7.0.2, Varnish Cache 6.0 LTS before 6.0.10, and and Varnish Enterprise (Cache Plus) 4.1.x before 4.1.11r6 and 6.0.x before 6.0.9r4, request smuggling can occur for HTTP/1 connections.

CVSS3: 9.1
nvd
около 4 лет назад

In Varnish Cache before 6.6.2 and 7.x before 7.0.2, Varnish Cache 6.0 LTS before 6.0.10, and and Varnish Enterprise (Cache Plus) 4.1.x before 4.1.11r6 and 6.0.x before 6.0.9r4, request smuggling can occur for HTTP/1 connections.

CVSS3: 9.1
debian
около 4 лет назад

In Varnish Cache before 6.6.2 and 7.x before 7.0.2, Varnish Cache 6.0 ...

rocky
около 4 лет назад

Important: varnish:6 security update

CVSS3: 9.1
github
почти 4 года назад

In Varnish Cache before 6.6.2 and 7.x before 7.0.2, Varnish Cache 6.0 LTS before 6.0.10, and and Varnish Enterprise (Cache Plus) 4.1.x before 4.1.11r6 and 6.0.x before 6.0.9r4, request smuggling can occur for HTTP/1 connections.

EPSS

Процентиль: 57%
0.00346
Низкий

9.1 Critical

CVSS3