In Varnish Cache before 6.6.2 and 7.x before 7.0.2, Varnish Cache 6.0 LTS before 6.0.10, and and Varnish Enterprise (Cache Plus) 4.1.x before 4.1.11r6 and 6.0.x before 6.0.9r4, request smuggling can occur for HTTP/1 connections.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-2920-1 | varnish security update |
Debian DSA |
DSA-5088-1 | varnish security update |
EUVD |
EUVD-2022-28875 | In Varnish Cache before 6.6.2 and 7.x before 7.0.2, Varnish Cache 6.0 LTS before 6.0.10, and and Varnish Enterprise (Cache Plus) 4.1.x before 4.1.11r6 and 6.0.x before 6.0.9r4, request smuggling can occur for HTTP/1 connections. |
Ubuntu USN |
USN-5474-1 | Varnish Cache vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-03T03:59:23.263Z
Reserved: 2022-01-26T00:00:00
Link: CVE-2022-23959
No data.
Status : Modified
Published: 2022-01-26T01:15:07.900
Modified: 2024-11-21T06:49:32.090
Link: CVE-2022-23959
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA
EUVD
Ubuntu USN