CVE-2022-23959
26.01.2022, 01:15
In Varnish Cache before 6.6.2 and 7.x before 7.0.2, Varnish Cache 6.0 LTS before 6.0.10, and and Varnish Enterprise (Cache Plus) 4.1.x before 4.1.11r6 and 6.0.x before 6.0.9r4, request smuggling can occur for HTTP/1 connections.
Vendor | Product | Version |
---|---|---|
varnish-software | varnich_cache | 1.0.0 ≤ 𝑥 < 6.6.2 |
varnish-software | varnich_cache | 4.1.1 ≤ 𝑥 < 4.1.11r6 |
varnish-software | varnich_cache | 4.1 |
varnish-software | varnish_cache | 6.0.0 ≤ 𝑥 < 6.0.10 |
varnish-software | varnish_cache_plus | 6.0.0 ≤ 𝑥 < 6.0.9r4 |
varnish_cache_project | varnish_cache | 7.0.0 ≤ 𝑥 < 7.0.2 |
debian | debian_linux | 9.0 |
debian | debian_linux | 10.0 |
debian | debian_linux | 11.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
References