vulnerability

Oracle Linux: CVE-2022-23959: ELSA-2022-0418: varnish:6 security update (IMPORTANT) (Multiple Advisories)

Severity
9
CVSS
(AV:N/AC:L/Au:N/C:C/I:C/A:N)
Published
Jan 25, 2022
Added
Feb 4, 2022
Modified
Dec 1, 2024

Description

In Varnish Cache before 6.6.2 and 7.x before 7.0.2, Varnish Cache 6.0 LTS before 6.0.10, and and Varnish Enterprise (Cache Plus) 4.1.x before 4.1.11r6 and 6.0.x before 6.0.9r4, request smuggling can occur for HTTP/1 connections.
A flaw was found in Varnish. This flaw allows an attacker to carry out a request smuggling attack on HTTP/1 connections on Varnish cache servers. This smuggled request goes through the usual Varnish Configuration Language (VCL) processing since the Varnish server treats it as an additional request.

Solution(s)

oracle-linux-upgrade-varnishoracle-linux-upgrade-varnish-develoracle-linux-upgrade-varnish-docsoracle-linux-upgrade-varnish-modules
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.