Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 12

Количество 12

fstec логотип

BDU:2024-03247

почти 4 года назад

Уязвимость кэш-сервера Varnish, связанная с подделкой запросов на стороне сервера, позволяющая нарушителю оказать воздействие на целостность защищаемой информации

CVSS3: 7.5
EPSS: Низкий
redos логотип

ROS-20240423-01

больше 2 лет назад

Множественные уязвимости varnish

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2022-45060

почти 4 года назад

An HTTP Request Forgery issue was discovered in Varnish Cache 5.x and 6.x before 6.0.11, 7.x before 7.1.2, and 7.2.x before 7.2.1. An attacker may introduce characters through HTTP/2 pseudo-headers that are invalid in the context of an HTTP/1 request line, causing the Varnish server to produce invalid HTTP/1 requests to the backend. This could, in turn, be used to exploit vulnerabilities in a server behind the Varnish server. Note: the 6.0.x LTS series (before 6.0.11) is affected.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2022-45060

почти 4 года назад

An HTTP Request Forgery issue was discovered in Varnish Cache 5.x and 6.x before 6.0.11, 7.x before 7.1.2, and 7.2.x before 7.2.1. An attacker may introduce characters through HTTP/2 pseudo-headers that are invalid in the context of an HTTP/1 request line, causing the Varnish server to produce invalid HTTP/1 requests to the backend. This could, in turn, be used to exploit vulnerabilities in a server behind the Varnish server. Note: the 6.0.x LTS series (before 6.0.11) is affected.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2022-45060

почти 4 года назад

An HTTP Request Forgery issue was discovered in Varnish Cache 5.x and 6.x before 6.0.11, 7.x before 7.1.2, and 7.2.x before 7.2.1. An attacker may introduce characters through HTTP/2 pseudo-headers that are invalid in the context of an HTTP/1 request line, causing the Varnish server to produce invalid HTTP/1 requests to the backend. This could, in turn, be used to exploit vulnerabilities in a server behind the Varnish server. Note: the 6.0.x LTS series (before 6.0.11) is affected.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2022-45060

почти 4 года назад

An HTTP Request Forgery issue was discovered in Varnish Cache 5.x and ...

CVSS3: 7.5
EPSS: Низкий
rocky логотип

RLSA-2022:8649

больше 3 лет назад

Important: varnish:6 security update

EPSS: Низкий
rocky логотип

RLSA-2022:8643

больше 3 лет назад

Important: varnish security update

EPSS: Низкий
github логотип

GHSA-78x9-jhxm-553x

почти 4 года назад

An HTTP Request Forgery issue was discovered in Varnish Cache 5.x and 6.x before 6.0.11, 7.x before 7.1.2, and 7.2.x before 7.2.1. An attacker may introduce characters through HTTP/2 pseudo-headers that are invalid in the context of an HTTP/1 request line, causing the Varnish server to produce invalid HTTP/1 requests to the backend. This could, in turn, be used to exploit vulnerabilities in a server behind the Varnish server. Note: the 6.0.x LTS series (before 6.0.11) is affected.

CVSS3: 7.5
EPSS: Низкий
oracle-oval логотип

ELSA-2022-8649

больше 3 лет назад

ELSA-2022-8649: varnish:6 security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2022-8643

больше 3 лет назад

ELSA-2022-8643: varnish security update (IMPORTANT)

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2022:10198-1

больше 3 лет назад

Security update for varnish

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2024-03247

Уязвимость кэш-сервера Varnish, связанная с подделкой запросов на стороне сервера, позволяющая нарушителю оказать воздействие на целостность защищаемой информации

CVSS3: 7.5
1%
Низкий
почти 4 года назад
redos логотип
ROS-20240423-01

Множественные уязвимости varnish

CVSS3: 7.5
больше 2 лет назад
ubuntu логотип
CVE-2022-45060

An HTTP Request Forgery issue was discovered in Varnish Cache 5.x and 6.x before 6.0.11, 7.x before 7.1.2, and 7.2.x before 7.2.1. An attacker may introduce characters through HTTP/2 pseudo-headers that are invalid in the context of an HTTP/1 request line, causing the Varnish server to produce invalid HTTP/1 requests to the backend. This could, in turn, be used to exploit vulnerabilities in a server behind the Varnish server. Note: the 6.0.x LTS series (before 6.0.11) is affected.

CVSS3: 7.5
1%
Низкий
почти 4 года назад
redhat логотип
CVE-2022-45060

An HTTP Request Forgery issue was discovered in Varnish Cache 5.x and 6.x before 6.0.11, 7.x before 7.1.2, and 7.2.x before 7.2.1. An attacker may introduce characters through HTTP/2 pseudo-headers that are invalid in the context of an HTTP/1 request line, causing the Varnish server to produce invalid HTTP/1 requests to the backend. This could, in turn, be used to exploit vulnerabilities in a server behind the Varnish server. Note: the 6.0.x LTS series (before 6.0.11) is affected.

CVSS3: 7.5
1%
Низкий
почти 4 года назад
nvd логотип
CVE-2022-45060

An HTTP Request Forgery issue was discovered in Varnish Cache 5.x and 6.x before 6.0.11, 7.x before 7.1.2, and 7.2.x before 7.2.1. An attacker may introduce characters through HTTP/2 pseudo-headers that are invalid in the context of an HTTP/1 request line, causing the Varnish server to produce invalid HTTP/1 requests to the backend. This could, in turn, be used to exploit vulnerabilities in a server behind the Varnish server. Note: the 6.0.x LTS series (before 6.0.11) is affected.

CVSS3: 7.5
1%
Низкий
почти 4 года назад
debian логотип
CVE-2022-45060

An HTTP Request Forgery issue was discovered in Varnish Cache 5.x and ...

CVSS3: 7.5
1%
Низкий
почти 4 года назад
rocky логотип
RLSA-2022:8649

Important: varnish:6 security update

1%
Низкий
больше 3 лет назад
rocky логотип
RLSA-2022:8643

Important: varnish security update

1%
Низкий
больше 3 лет назад
github логотип
GHSA-78x9-jhxm-553x

An HTTP Request Forgery issue was discovered in Varnish Cache 5.x and 6.x before 6.0.11, 7.x before 7.1.2, and 7.2.x before 7.2.1. An attacker may introduce characters through HTTP/2 pseudo-headers that are invalid in the context of an HTTP/1 request line, causing the Varnish server to produce invalid HTTP/1 requests to the backend. This could, in turn, be used to exploit vulnerabilities in a server behind the Varnish server. Note: the 6.0.x LTS series (before 6.0.11) is affected.

CVSS3: 7.5
1%
Низкий
почти 4 года назад
oracle-oval логотип
ELSA-2022-8649

ELSA-2022-8649: varnish:6 security update (IMPORTANT)

1%
Низкий
больше 3 лет назад
oracle-oval логотип
ELSA-2022-8643

ELSA-2022-8643: varnish security update (IMPORTANT)

1%
Низкий
больше 3 лет назад
suse-cvrf логотип
openSUSE-SU-2022:10198-1

Security update for varnish

больше 3 лет назад

Уязвимостей на страницу