9.1
CVSSv3

CVE-2022-23959

Published: 26/01/2022 Updated: 07/11/2023
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
CVSS v3 Base Score: 9.1 | Impact Score: 5.2 | Exploitability Score: 3.9
VMScore: 570
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N

Vulnerability Summary

In Varnish Cache prior to 6.6.2 and 7.x prior to 7.0.2, Varnish Cache 6.0 LTS prior to 6.0.10, and and Varnish Enterprise (Cache Plus) 4.1.x prior to 4.1.11r6 and 6.0.x prior to 6.0.9r4, request smuggling can occur for HTTP/1 connections.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

varnish-software varnich cache 4.1

varnish-software varnich cache

varnish cache project varnish cache

varnish-software varnish cache

varnish-software varnish cache plus

fedoraproject fedora 35

debian debian linux 9.0

debian debian linux 10.0

debian debian linux 11.0

Vendor Advisories

Debian Bug report logs - #1004433 CVE-2022-23959: VSV00008 Varnish HTTP/1 Request Smuggling Vulnerability Package: varnish; Maintainer for varnish is Varnish Package Maintainers <team+varnish-team@trackerdebianorg>; Source for varnish is src:varnish (PTS, buildd, popcon) Reported by: Andreas Unterkircher <unki@netshadow ...
Several security issues were fixed in Varnish Cache ...
Brief introduction CVE-2021-36740 Martin Blix Grydeland discovered that Varnish is vulnerable to request smuggling attacks if the HTTP/2 protocol is enabled CVE-2022-23959 James Kettle discovered a request smuggling attack against the HTTP/1 protocol implementation in Varnish For the oldstable distribution (buster), these probl ...
Synopsis Important: varnish:6 security update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for the varnish:6 module is now available for Red Hat Enterprise Linux 81 Update Services for SAP SolutionsRed Hat ...
Synopsis Important: varnish:6 security update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for the varnish:6 module is now available for Red Hat Enterprise Linux 84 Extended Update SupportRed Hat Product Se ...
Synopsis Important: rh-varnish6-varnish security update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for rh-varnish6-varnish is now available for Red Hat Software CollectionsRed Hat Product Security has rate ...
Synopsis Important: varnish:6 security update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for the varnish:6 module is now available for Red Hat Enterprise Linux 82 Extended Update SupportRed Hat Product Se ...
Synopsis Important: varnish:6 security update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for the varnish:6 module is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rated this upda ...
A flaw was found in Varnish This flaw allows an attacker to carry out a request smuggling attack on HTTP/1 connections on Varnish cache servers This smuggled request goes through the usual Varnish Configuration Language (VCL) processing since the Varnish server treats it as an additional request (CVE-2022-23959) ...
In Varnish Cache before 662 and 7x before 702, Varnish Cache 60 LTS before 6010, and and Varnish Enterprise (Cache Plus) 41x before 4111r6 and 60x before 609r4, request smuggling can occur for HTTP/1 connections ...