CVE-2022-23959

Description

In Varnish Cache before 6.6.2 and 7.x before 7.0.2, Varnish Cache 6.0 LTS before 6.0.10, and and Varnish Enterprise (Cache Plus) 4.1.x before 4.1.11r6 and 6.0.x before 6.0.9r4, request smuggling can occur for HTTP/1 connections.

Risk Information

Base Score
9.1
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
EPSS Score
Exploitation Probability
0.346

Associated Vulnerability

VulnerabilityOS Platform
(RHSA-2022:0418) varnish:6 security update varnish-6.0.8-1.module+el8.5.0+14089+03a0c2cc.1.x86_64.rpmLinux
(RHSA-2022:0418) varnish:6 security update varnish-devel-6.0.8-1.module+el8.5.0+14089+03a0c2cc.1.x86_64.rpmLinux
(RHSA-2022:0418) varnish:6 security update varnish-docs-6.0.8-1.module+el8.5.0+14089+03a0c2cc.1.x86_64.rpmLinux
(RHSA-2022:0418) varnish:6 security update varnish-modules-0.15.0-6.module+el8.5.0+11976+0b4af72d.x86_64.rpmLinux
(RHSA-2022:0418) varnish:6 security update varnish-modules-debugsource-0.15.0-6.module+el8.5.0+11976+0b4af72d.x86_64.rpmLinux
Varnish update (ELSA-2022-0418) varnish-6.0.8-1.module+el8.5.0+20491+1af4e193.1.x86_64.rpmLinux
Varnish-devel update (ELSA-2022-0418) varnish-devel-6.0.8-1.module+el8.5.0+20491+1af4e193.1.x86_64.rpmLinux
Varnish-docs update (ELSA-2022-0418) varnish-docs-6.0.8-1.module+el8.5.0+20491+1af4e193.1.x86_64.rpmLinux
Varnish-modules update (ELSA-2022-0418) varnish-modules-0.15.0-6.module+el8.5.0+20320+0b4af72d.x86_64.rpmLinux
varnish security update(DSA-5088-1) varnish_6.1.1-1+deb10u3_i386.debLinux
varnish security update(DSA-5088-1) varnish_6.1.1-1+deb10u3_amd64.debLinux
varnish security update(DSA-5088-1) varnish_6.5.1-1+deb11u2_amd64.debLinux
state of the art, high-performance web accelerator (USN-5474-1) varnish_5.2.1-1ubuntu0.1_i386.debLinux
state of the art, high-performance web accelerator (USN-5474-1) varnish_5.2.1-1ubuntu0.1_amd64.debLinux
state of the art, high-performance web accelerator (USN-5474-1) varnish_6.2.1-2ubuntu0.2_amd64.debLinux
state of the art, high-performance web accelerator (USN-5474-1) varnish_6.5.2-1ubuntu0.2_amd64.debLinux
state of the art, high-performance web accelerator (USN-5474-1) varnish_6.6.1-1ubuntu0.2_amd64.debLinux
state of the art, high-performance web accelerator (USN-5474-1) libvarnishapi1_5.2.1-1ubuntu0.1_i386.debLinux
state of the art, high-performance web accelerator (USN-5474-1) libvarnishapi1_5.2.1-1ubuntu0.1_amd64.debLinux
state of the art, high-performance web accelerator (USN-5474-1) libvarnishapi2_6.2.1-2ubuntu0.2_amd64.debLinux
state of the art, high-performance web accelerator (USN-5474-1) libvarnishapi2_6.5.2-1ubuntu0.2_amd64.debLinux
state of the art, high-performance web accelerator (USN-5474-1) libvarnishapi2_6.6.1-1ubuntu0.2_amd64.debLinux
Varnish update (ELSA-2022-8649) varnish-6.0.8-2.module+el8.7.0+20885+cb213da4.1.x86_64.rpmLinux
Varnish-devel update (ELSA-2022-8649) varnish-devel-6.0.8-2.module+el8.7.0+20885+cb213da4.1.x86_64.rpmLinux
Varnish-docs update (ELSA-2022-8649) varnish-docs-6.0.8-2.module+el8.7.0+20885+cb213da4.1.x86_64.rpmLinux
Varnish-modules update (ELSA-2022-8649) varnish-modules-0.15.0-6.module+el8.5.0+20320+0b4af72d.x86_64.rpmLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234