Логотип exploitDog
bind:"CVE-2022-45060"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2022-45060"

Количество 12

Количество 12

ubuntu логотип

CVE-2022-45060

почти 3 года назад

An HTTP Request Forgery issue was discovered in Varnish Cache 5.x and 6.x before 6.0.11, 7.x before 7.1.2, and 7.2.x before 7.2.1. An attacker may introduce characters through HTTP/2 pseudo-headers that are invalid in the context of an HTTP/1 request line, causing the Varnish server to produce invalid HTTP/1 requests to the backend. This could, in turn, be used to exploit vulnerabilities in a server behind the Varnish server. Note: the 6.0.x LTS series (before 6.0.11) is affected.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2022-45060

почти 3 года назад

An HTTP Request Forgery issue was discovered in Varnish Cache 5.x and 6.x before 6.0.11, 7.x before 7.1.2, and 7.2.x before 7.2.1. An attacker may introduce characters through HTTP/2 pseudo-headers that are invalid in the context of an HTTP/1 request line, causing the Varnish server to produce invalid HTTP/1 requests to the backend. This could, in turn, be used to exploit vulnerabilities in a server behind the Varnish server. Note: the 6.0.x LTS series (before 6.0.11) is affected.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2022-45060

почти 3 года назад

An HTTP Request Forgery issue was discovered in Varnish Cache 5.x and 6.x before 6.0.11, 7.x before 7.1.2, and 7.2.x before 7.2.1. An attacker may introduce characters through HTTP/2 pseudo-headers that are invalid in the context of an HTTP/1 request line, causing the Varnish server to produce invalid HTTP/1 requests to the backend. This could, in turn, be used to exploit vulnerabilities in a server behind the Varnish server. Note: the 6.0.x LTS series (before 6.0.11) is affected.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2022-45060

почти 3 года назад

An HTTP Request Forgery issue was discovered in Varnish Cache 5.x and ...

CVSS3: 7.5
EPSS: Низкий
rocky логотип

RLSA-2022:8649

почти 3 года назад

Important: varnish:6 security update

EPSS: Низкий
rocky логотип

RLSA-2022:8643

почти 3 года назад

Important: varnish security update

EPSS: Низкий
github логотип

GHSA-78x9-jhxm-553x

почти 3 года назад

An HTTP Request Forgery issue was discovered in Varnish Cache 5.x and 6.x before 6.0.11, 7.x before 7.1.2, and 7.2.x before 7.2.1. An attacker may introduce characters through HTTP/2 pseudo-headers that are invalid in the context of an HTTP/1 request line, causing the Varnish server to produce invalid HTTP/1 requests to the backend. This could, in turn, be used to exploit vulnerabilities in a server behind the Varnish server. Note: the 6.0.x LTS series (before 6.0.11) is affected.

CVSS3: 7.5
EPSS: Низкий
oracle-oval логотип

ELSA-2022-8649

почти 3 года назад

ELSA-2022-8649: varnish:6 security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2022-8643

почти 3 года назад

ELSA-2022-8643: varnish security update (IMPORTANT)

EPSS: Низкий
fstec логотип

BDU:2024-03247

почти 3 года назад

Уязвимость кэш-сервера Varnish, связанная с подделкой запросов на стороне сервера, позволяющая нарушителю оказать воздействие на целостность защищаемой информации

CVSS3: 7.5
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2022:10198-1

почти 3 года назад

Security update for varnish

EPSS: Низкий
redos логотип

ROS-20240423-01

больше 1 года назад

Множественные уязвимости varnish

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2022-45060

An HTTP Request Forgery issue was discovered in Varnish Cache 5.x and 6.x before 6.0.11, 7.x before 7.1.2, and 7.2.x before 7.2.1. An attacker may introduce characters through HTTP/2 pseudo-headers that are invalid in the context of an HTTP/1 request line, causing the Varnish server to produce invalid HTTP/1 requests to the backend. This could, in turn, be used to exploit vulnerabilities in a server behind the Varnish server. Note: the 6.0.x LTS series (before 6.0.11) is affected.

CVSS3: 7.5
1%
Низкий
почти 3 года назад
redhat логотип
CVE-2022-45060

An HTTP Request Forgery issue was discovered in Varnish Cache 5.x and 6.x before 6.0.11, 7.x before 7.1.2, and 7.2.x before 7.2.1. An attacker may introduce characters through HTTP/2 pseudo-headers that are invalid in the context of an HTTP/1 request line, causing the Varnish server to produce invalid HTTP/1 requests to the backend. This could, in turn, be used to exploit vulnerabilities in a server behind the Varnish server. Note: the 6.0.x LTS series (before 6.0.11) is affected.

CVSS3: 7.5
1%
Низкий
почти 3 года назад
nvd логотип
CVE-2022-45060

An HTTP Request Forgery issue was discovered in Varnish Cache 5.x and 6.x before 6.0.11, 7.x before 7.1.2, and 7.2.x before 7.2.1. An attacker may introduce characters through HTTP/2 pseudo-headers that are invalid in the context of an HTTP/1 request line, causing the Varnish server to produce invalid HTTP/1 requests to the backend. This could, in turn, be used to exploit vulnerabilities in a server behind the Varnish server. Note: the 6.0.x LTS series (before 6.0.11) is affected.

CVSS3: 7.5
1%
Низкий
почти 3 года назад
debian логотип
CVE-2022-45060

An HTTP Request Forgery issue was discovered in Varnish Cache 5.x and ...

CVSS3: 7.5
1%
Низкий
почти 3 года назад
rocky логотип
RLSA-2022:8649

Important: varnish:6 security update

1%
Низкий
почти 3 года назад
rocky логотип
RLSA-2022:8643

Important: varnish security update

1%
Низкий
почти 3 года назад
github логотип
GHSA-78x9-jhxm-553x

An HTTP Request Forgery issue was discovered in Varnish Cache 5.x and 6.x before 6.0.11, 7.x before 7.1.2, and 7.2.x before 7.2.1. An attacker may introduce characters through HTTP/2 pseudo-headers that are invalid in the context of an HTTP/1 request line, causing the Varnish server to produce invalid HTTP/1 requests to the backend. This could, in turn, be used to exploit vulnerabilities in a server behind the Varnish server. Note: the 6.0.x LTS series (before 6.0.11) is affected.

CVSS3: 7.5
1%
Низкий
почти 3 года назад
oracle-oval логотип
ELSA-2022-8649

ELSA-2022-8649: varnish:6 security update (IMPORTANT)

почти 3 года назад
oracle-oval логотип
ELSA-2022-8643

ELSA-2022-8643: varnish security update (IMPORTANT)

почти 3 года назад
fstec логотип
BDU:2024-03247

Уязвимость кэш-сервера Varnish, связанная с подделкой запросов на стороне сервера, позволяющая нарушителю оказать воздействие на целостность защищаемой информации

CVSS3: 7.5
1%
Низкий
почти 3 года назад
suse-cvrf логотип
openSUSE-SU-2022:10198-1

Security update for varnish

почти 3 года назад
redos логотип
ROS-20240423-01

Множественные уязвимости varnish

CVSS3: 7.5
больше 1 года назад

Уязвимостей на страницу