Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-47905

Опубликовано: 13 мая 2025
Источник: redhat
CVSS3: 8.1
EPSS Низкий

Описание

Varnish Cache before 7.6.3 and 7.7 before 7.7.1, and Varnish Enterprise before 6.0.13r14, allow client-side desync via HTTP/1 requests, because the product incorrectly permits CRLF to be skipped to delimit chunk boundaries.

A vulnerability was found in Varnish Cache. This vulnerability may allow request smuggling attacks, where a malicious actor can craft seemingly legitimate HTTP requests. This issue could result in an unspecified system caching incorrect content that can expose confidential information.

Отчет

This vulnerability is rated as an IMPORTANT severity because this is a client-side desync vulnerability in Varnish handling a chunked transfer encoding, where it mishandles CRLF delimiters, allows attackers to smuggle additional HTTP/1 requests, this flaw allows attacker to unauthorized access of sensitive information and data alteration.

Меры по смягчению последствий

Currently, no mitigation is available for this vulnerability.

Дополнительная информация

Статус:

Important
Дефект:
CWE-444
https://bugzilla.redhat.com/show_bug.cgi?id=2364235varnish: request smuggling attacks

EPSS

Процентиль: 16%
0.00051
Низкий

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 5.4
ubuntu
3 месяца назад

Varnish Cache before 7.6.3 and 7.7 before 7.7.1, and Varnish Enterprise before 6.0.13r14, allow client-side desync via HTTP/1 requests, because the product incorrectly permits CRLF to be skipped to delimit chunk boundaries.

CVSS3: 5.4
nvd
3 месяца назад

Varnish Cache before 7.6.3 and 7.7 before 7.7.1, and Varnish Enterprise before 6.0.13r14, allow client-side desync via HTTP/1 requests, because the product incorrectly permits CRLF to be skipped to delimit chunk boundaries.

CVSS3: 5.4
debian
3 месяца назад

Varnish Cache before 7.6.3 and 7.7 before 7.7.1, and Varnish Enterpris ...

CVSS3: 5.4
github
3 месяца назад

Varnish Cache before 7.6.3 and 7.7 before 7.7.1, and Varnish Enterprise before 6.0.13r14, allow client-side desync via HTTP/1 requests, because the product incorrectly permits CRLF to be skipped to delimit chunk boundaries.

oracle-oval
около 1 месяца назад

ELSA-2025-8550: varnish security update (IMPORTANT)

EPSS

Процентиль: 16%
0.00051
Низкий

8.1 High

CVSS3