ZeroHour

CVE-2022-23959

CVSS 3.1
9.1 critical
EPSS
2%p79
Published
()
Modified
Description

In Varnish Cache before 6.6.2 and 7.x before 7.0.2, Varnish Cache 6.0 LTS before 6.0.10, and and Varnish Enterprise (Cache Plus) 4.1.x before 4.1.11r6 and 6.0.x before 6.0.9r4, request smuggling can occur for HTTP/1 connections.

Vendors
varnish-softwarevarnish cache projectfedoraprojectdebian
Products
varnich cache, varnish cache, varnish cache plus, fedora, debian linux
Weakness
CWE-444
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.