Varnish 3.x before 3.0.7, when used in certain stacked installations, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a header line terminated by a \r (carriage return) character in conjunction with multiple Content-Length headers in an HTTP request.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux | — | Upgrade varnish | Jul 14, 2016 | Apr 25, 2016 |
| Debian | — | Upgrade varnish | Apr 22, 2016 | Apr 22, 2016 |
| Gentoo Linux | — | Upgrade www-servers/varnish. | Oct 30, 2017 | Apr 25, 2016 |
| Suse | — | Upgrade varnish-debugsourceUpgrade libvarnishapi1Upgrade varnishUpgrade varnish-debuginfoUpgrade libvarnishapi1-debuginfoUpgrade varnish-devel | May 17, 2016 | Apr 25, 2016 |
| Ubuntu | — | Upgrade varnish | Nov 19, 2024 | Apr 25, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub