Описание
Varnish Cache before 8.0.1 and Varnish Enterprise before 6.0.16r12, in certain unchecked req.url scenarios, mishandle URLs with a path of / for HTTP/1.1, potentially leading to cache poisoning or authentication bypass.
A flaw was found in Varnish Cache and Varnish Enterprise. A remote attacker could exploit this vulnerability by sending specially crafted HTTP/1.1 requests with a path of / in the URL. This mishandling of URLs, specifically in unchecked req.url scenarios, could lead to cache poisoning, where an attacker manipulates cached content, or an authentication bypass, allowing unauthorized access.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | redhat-user-workloads/varnish-7-10-0 | Not affected | ||
| Red Hat Enterprise Linux 10 | redhat-user-workloads/varnish-7-10-1 | Not affected | ||
| Red Hat Enterprise Linux 10 | varnish | Fix deferred | ||
| Red Hat Enterprise Linux 10 | varnish-modules | Fix deferred | ||
| Red Hat Enterprise Linux 8 | redhat-user-workloads/varnish-6-8-10 | Not affected | ||
| Red Hat Enterprise Linux 8 | varnish:6/varnish | Fix deferred | ||
| Red Hat Enterprise Linux 8 | varnish:6/varnish-modules | Fix deferred | ||
| Red Hat Enterprise Linux 9 | redhat-user-workloads/varnish-6-9-6 | Not affected | ||
| Red Hat Enterprise Linux 9 | redhat-user-workloads/varnish-6-9-7 | Not affected | ||
| Red Hat Enterprise Linux 9 | varnish | Not affected |
Показывать по
Дополнительная информация
Статус:
5.4 Medium
CVSS3
Связанные уязвимости
Varnish Cache before 8.0.1 and Varnish Enterprise before 6.0.16r12, in certain unchecked req.url scenarios, mishandle URLs with a path of / for HTTP/1.1, potentially leading to cache poisoning or authentication bypass.
Varnish Cache before 8.0.1 and Varnish Enterprise before 6.0.16r12, in certain unchecked req.url scenarios, mishandle URLs with a path of / for HTTP/1.1, potentially leading to cache poisoning or authentication bypass.
Varnish Cache before 8.0.1 and Varnish Enterprise before 6.0.16r12, in ...
Varnish Cache before 8.0.1 and Varnish Enterprise before 6.0.16r12, in certain unchecked req.url scenarios, mishandle URLs with a path of / for HTTP/1.1, potentially leading to cache poisoning or authentication bypass.
5.4 Medium
CVSS3