CVE-2022-38150: High severity varnish cache vulnerability
In Varnish Cache 7.0.0, 7.0.1, 7.0.2, and 7.1.0, it is possible to cause the Varnish Server to assert and automatically restart through forged HTTP/1 backend responses. An attack uses a crafted reason phrase of the backend response status line. This is fixed in 7.0.3 and 7.1.1.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-38150?
CVE-2022-38150 is a vulnerability in Varnish Cache versions 7.0.0, 7.0.1, 7.0.2, and 7.1.0 that allows an attacker to cause the server to assert and automatically restart through forged HTTP/1 backend responses.
How does CVE-2022-38150 affect Varnish Cache?
CVE-2022-38150 affects Varnish Cache versions 7.0.0, 7.0.1, 7.0.2, and 7.1.0.
What is the severity of CVE-2022-38150?
The severity of CVE-2022-38150 is high with a severity score of 7.5.
How can I fix CVE-2022-38150?
To fix CVE-2022-38150, you should upgrade to Varnish Cache version 7.0.3 or 7.1.1, as this vulnerability is fixed in these versions.
Where can I find more information about CVE-2022-38150?
You can find more information about CVE-2022-38150 at the following references: [Reference 1](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/M4KVVCIQVINQQ2D7ORNARSYALMJUMP3I/), [Reference 2](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TW3X4PEKC5C736SCKE2UG3Y7JWKMD2K6/), [Reference 3](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/V2BUKFICLZBXESLQ3MXMIG3G52RZURFK/)