CVE-2022-23959
Summary
| CVE | CVE-2022-23959 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-01-26 01:15:00 UTC |
| Updated | 2023-11-07 03:44:00 UTC |
| Description | In Varnish Cache before 6.6.2 and 7.x before 7.0.2, Varnish Cache 6.0 LTS before 6.0.10, and and Varnish Enterprise (Cache Plus) 4.1.x before 4.1.11r6 and 6.0.x before 6.0.9r4, request smuggling can occur for HTTP/1 connections. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [SECURITY] [DLA 2920-1] varnish security update |
MLIST |
lists.debian.org |
|
| [SECURITY] Fedora 35 Update: varnish-6.6.2-2.fc35 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| Varnish HTTP/1 Request Smuggling -
Varnish Software Documentation |
MISC |
docs.varnish-software.com |
|
| Debian -- Security Information -- DSA-5088-1 varnish |
DEBIAN |
www.debian.org |
|
| VSV00008 Varnish HTTP/1 Request Smuggling Vulnerability — Varnish HTTP Cache |
MISC |
varnish-cache.org |
|
| [SECURITY] Fedora 35 Update: varnish-6.6.2-2.fc35 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 159626 Oracle Enterprise Linux Security Update for varnish:6 (ELSA-2022-0418)
- 179072 Debian Security Update for varnish (DLA 2920-1)
- 179098 Debian Security Update for varnish (DSA 5088-1)
- 182438 Debian Security Update for varnish (CVE-2022-23959)
- 198827 Ubuntu Security Notification for Varnish Cache Vulnerabilities (USN-5474-1)
- 240061 Red Hat Update for varnish:6 (RHSA-2022:0418)
- 240063 Red Hat Update for varnish:6 (RHSA-2022:0422)
- 240064 Red Hat Update for varnish:6 (RHSA-2022:0421)
- 240365 Red Hat Update for rh-varnish6-varnish (RHSA-2022:4745)
- 240438 Red Hat Update for varnish:6 (RHSA-2022:0420)
- 282392 Fedora Security Update for varnish (FEDORA-2022-2f14ec7663)
- 354047 Amazon Linux Security Advisory for varnish : ALAS-2022-1632
- 376890 Alibaba Cloud Linux Security Update for varnish:6 (ALINUX3-SA-2022:0024)
- 500720 Alpine Linux Security Update for varnish
- 501789 Alpine Linux Security Update for varnish
- 502036 Alpine Linux Security Update for varnish
- 504494 Alpine Linux Security Update for varnish
- 690775 Free Berkeley Software Distribution (FreeBSD) Security Update for varnish (b0c83e1a-8153-11ec-84f9-641c67a117d8)
- 940449 AlmaLinux Security Update for varnish:6 (ALSA-2022:0418)
- 960809 Rocky Linux Security Update for varnish:6 (RLSA-2022:0418)