CVE-2022-23959 Information
Jun 07, 2022
cve
Description
In Varnish Cache before 6.6.2 and 7.x before 7.0.2 Varnish Cache 6.0 LTS before 6.0.10 and and Varnish Enterprise (Cache Plus) 4.1.x before 4.1.11r6 and 6.0.x before 6.0.9r4 request smuggling can occur for HTTP/1 connections.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Reference
https://varnish-cache.org/security/VSV00008.html https://docs.varnish-software.com/security/VSV00008/ https://lists.debian.org/debian-lts-announce/2022/02/msg00014.html https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UMMDMQWNAE3BTSZUHXQHVAMZC5TLHLYT/ https://www.debian.org/security/2022/dsa-5088
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
NONE
Base Severity
9.1
Share on: