Логотип exploitDog
bind:CVE-2022-45060
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-45060

Количество 12

Количество 12

ubuntu логотип

CVE-2022-45060

больше 2 лет назад

An HTTP Request Forgery issue was discovered in Varnish Cache 5.x and 6.x before 6.0.11, 7.x before 7.1.2, and 7.2.x before 7.2.1. An attacker may introduce characters through HTTP/2 pseudo-headers that are invalid in the context of an HTTP/1 request line, causing the Varnish server to produce invalid HTTP/1 requests to the backend. This could, in turn, be used to exploit vulnerabilities in a server behind the Varnish server. Note: the 6.0.x LTS series (before 6.0.11) is affected.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2022-45060

больше 2 лет назад

An HTTP Request Forgery issue was discovered in Varnish Cache 5.x and 6.x before 6.0.11, 7.x before 7.1.2, and 7.2.x before 7.2.1. An attacker may introduce characters through HTTP/2 pseudo-headers that are invalid in the context of an HTTP/1 request line, causing the Varnish server to produce invalid HTTP/1 requests to the backend. This could, in turn, be used to exploit vulnerabilities in a server behind the Varnish server. Note: the 6.0.x LTS series (before 6.0.11) is affected.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2022-45060

больше 2 лет назад

An HTTP Request Forgery issue was discovered in Varnish Cache 5.x and 6.x before 6.0.11, 7.x before 7.1.2, and 7.2.x before 7.2.1. An attacker may introduce characters through HTTP/2 pseudo-headers that are invalid in the context of an HTTP/1 request line, causing the Varnish server to produce invalid HTTP/1 requests to the backend. This could, in turn, be used to exploit vulnerabilities in a server behind the Varnish server. Note: the 6.0.x LTS series (before 6.0.11) is affected.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2022-45060

больше 2 лет назад

An HTTP Request Forgery issue was discovered in Varnish Cache 5.x and ...

CVSS3: 7.5
EPSS: Низкий
rocky логотип

RLSA-2022:8649

больше 2 лет назад

Important: varnish:6 security update

EPSS: Низкий
rocky логотип

RLSA-2022:8643

больше 2 лет назад

Important: varnish security update

EPSS: Низкий
github логотип

GHSA-78x9-jhxm-553x

больше 2 лет назад

An HTTP Request Forgery issue was discovered in Varnish Cache 5.x and 6.x before 6.0.11, 7.x before 7.1.2, and 7.2.x before 7.2.1. An attacker may introduce characters through HTTP/2 pseudo-headers that are invalid in the context of an HTTP/1 request line, causing the Varnish server to produce invalid HTTP/1 requests to the backend. This could, in turn, be used to exploit vulnerabilities in a server behind the Varnish server. Note: the 6.0.x LTS series (before 6.0.11) is affected.

CVSS3: 7.5
EPSS: Низкий
oracle-oval логотип

ELSA-2022-8649

больше 2 лет назад

ELSA-2022-8649: varnish:6 security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2022-8643

больше 2 лет назад

ELSA-2022-8643: varnish security update (IMPORTANT)

EPSS: Низкий
fstec логотип

BDU:2024-03247

больше 2 лет назад

Уязвимость кэш-сервера Varnish, связанная с подделкой запросов на стороне сервера, позволяющая нарушителю оказать воздействие на целостность защищаемой информации

CVSS3: 7.5
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2022:10198-1

больше 2 лет назад

Security update for varnish

EPSS: Низкий
redos логотип

ROS-20240423-01

около 1 года назад

Множественные уязвимости varnish

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2022-45060

An HTTP Request Forgery issue was discovered in Varnish Cache 5.x and 6.x before 6.0.11, 7.x before 7.1.2, and 7.2.x before 7.2.1. An attacker may introduce characters through HTTP/2 pseudo-headers that are invalid in the context of an HTTP/1 request line, causing the Varnish server to produce invalid HTTP/1 requests to the backend. This could, in turn, be used to exploit vulnerabilities in a server behind the Varnish server. Note: the 6.0.x LTS series (before 6.0.11) is affected.

CVSS3: 7.5
0%
Низкий
больше 2 лет назад
redhat логотип
CVE-2022-45060

An HTTP Request Forgery issue was discovered in Varnish Cache 5.x and 6.x before 6.0.11, 7.x before 7.1.2, and 7.2.x before 7.2.1. An attacker may introduce characters through HTTP/2 pseudo-headers that are invalid in the context of an HTTP/1 request line, causing the Varnish server to produce invalid HTTP/1 requests to the backend. This could, in turn, be used to exploit vulnerabilities in a server behind the Varnish server. Note: the 6.0.x LTS series (before 6.0.11) is affected.

CVSS3: 7.5
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2022-45060

An HTTP Request Forgery issue was discovered in Varnish Cache 5.x and 6.x before 6.0.11, 7.x before 7.1.2, and 7.2.x before 7.2.1. An attacker may introduce characters through HTTP/2 pseudo-headers that are invalid in the context of an HTTP/1 request line, causing the Varnish server to produce invalid HTTP/1 requests to the backend. This could, in turn, be used to exploit vulnerabilities in a server behind the Varnish server. Note: the 6.0.x LTS series (before 6.0.11) is affected.

CVSS3: 7.5
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2022-45060

An HTTP Request Forgery issue was discovered in Varnish Cache 5.x and ...

CVSS3: 7.5
0%
Низкий
больше 2 лет назад
rocky логотип
RLSA-2022:8649

Important: varnish:6 security update

0%
Низкий
больше 2 лет назад
rocky логотип
RLSA-2022:8643

Important: varnish security update

0%
Низкий
больше 2 лет назад
github логотип
GHSA-78x9-jhxm-553x

An HTTP Request Forgery issue was discovered in Varnish Cache 5.x and 6.x before 6.0.11, 7.x before 7.1.2, and 7.2.x before 7.2.1. An attacker may introduce characters through HTTP/2 pseudo-headers that are invalid in the context of an HTTP/1 request line, causing the Varnish server to produce invalid HTTP/1 requests to the backend. This could, in turn, be used to exploit vulnerabilities in a server behind the Varnish server. Note: the 6.0.x LTS series (before 6.0.11) is affected.

CVSS3: 7.5
0%
Низкий
больше 2 лет назад
oracle-oval логотип
ELSA-2022-8649

ELSA-2022-8649: varnish:6 security update (IMPORTANT)

больше 2 лет назад
oracle-oval логотип
ELSA-2022-8643

ELSA-2022-8643: varnish security update (IMPORTANT)

больше 2 лет назад
fstec логотип
BDU:2024-03247

Уязвимость кэш-сервера Varnish, связанная с подделкой запросов на стороне сервера, позволяющая нарушителю оказать воздействие на целостность защищаемой информации

CVSS3: 7.5
0%
Низкий
больше 2 лет назад
suse-cvrf логотип
openSUSE-SU-2022:10198-1

Security update for varnish

больше 2 лет назад
redos логотип
ROS-20240423-01

Множественные уязвимости varnish

CVSS3: 7.5
около 1 года назад

Уязвимостей на страницу