Vulnerability Description
In Varnish Cache before 6.6.2 and 7.x before 7.0.2, Varnish Cache 6.0 LTS before 6.0.10, and and Varnish Enterprise (Cache Plus) 4.1.x before 4.1.11r6 and 6.0.x before 6.0.9r4, request smuggling can occur for HTTP/1 connections.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Varnish-Software | Varnich Cache | >= 1.0.0, < 6.6.2 |
| Varnish-Software | Varnish Cache | >= 6.0.0, < 6.0.10 |
| Varnish-Software | Varnish Cache Plus | >= 6.0.0, < 6.0.9r4 |
| Varnish Cache Project | Varnish Cache | >= 7.0.0, < 7.0.2 |
| Fedoraproject | Fedora | 35 |
| Debian | Debian Linux | 9.0 |
Related Weaknesses (CWE)
References
- https://docs.varnish-software.com/security/VSV00008/MitigationVendor Advisory
- https://lists.debian.org/debian-lts-announce/2022/02/msg00014.htmlMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://varnish-cache.org/security/VSV00008.htmlMitigationVendor Advisory
- https://www.debian.org/security/2022/dsa-5088Third Party Advisory
- https://docs.varnish-software.com/security/VSV00008/MitigationVendor Advisory
- https://lists.debian.org/debian-lts-announce/2022/02/msg00014.htmlMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://varnish-cache.org/security/VSV00008.htmlMitigationVendor Advisory
- https://www.debian.org/security/2022/dsa-5088Third Party Advisory
FAQ
What is CVE-2022-23959?
CVE-2022-23959 is a vulnerability with a CVSS score of 9.1 (CRITICAL). In Varnish Cache before 6.6.2 and 7.x before 7.0.2, Varnish Cache 6.0 LTS before 6.0.10, and and Varnish Enterprise (Cache Plus) 4.1.x before 4.1.11r6 and 6.0.x before 6.0.9r4, request smuggling can o...
How severe is CVE-2022-23959?
CVE-2022-23959 has been rated CRITICAL with a CVSS base score of 9.1/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2022-23959?
Check the references section above for vendor advisories and patch information. Affected products include: Varnish-Software Varnich Cache, Varnish-Software Varnish Cache, Varnish-Software Varnish Cache Plus, Varnish Cache Project Varnish Cache, Fedoraproject Fedora.