CVE-2022-38150 Information
Aug 12, 2022
cve
Description
In Varnish Cache 7.0.0 7.0.1 7.0.2 and 7.1.0 it is possible to cause the Varnish Server to assert and automatically restart through forged HTTP/1 backend responses. An attack uses a crafted reason phrase of the backend response status line. This is fixed in 7.0.3 and 7.1.1.
Reference
https://varnish-cache.org/security/VSV00009.html
Share on: