CVE-2022-45059: High severity Varnish Cache Project Varnish Cache vulnerability
An issue was discovered in Varnish Cache 7.x before 7.1.2 and 7.2.x before 7.2.1. A request smuggling attack can be performed on Varnish Cache servers by requesting that certain headers are made hop-by-hop, preventing the Varnish Cache servers from forwarding critical headers to the backend.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/varnishto a version that resolves this vulnerability.Fixed in 6.1.1-1+deb10u3Fixed in 6.1.1-1+deb10u4Fixed in 6.5.1-1+deb11u3Fixed in 7.1.1-1.1
Event History
Frequently Asked Questions
What is CVE-2022-45059?
CVE-2022-45059 refers to an issue discovered in Varnish Cache, which allows for a request smuggling attack by manipulating certain headers.
How does CVE-2022-45059 affect Varnish Cache servers?
CVE-2022-45059 affects Varnish Cache 7.x before 7.1.2 and 7.2.x before 7.2.1, allowing for request smuggling attacks that prevent critical headers from being forwarded to the backend.
What is the severity of CVE-2022-45059?
The severity of CVE-2022-45059 is high, with a severity value of 7.5.
Which software versions are affected by CVE-2022-45059?
Varnish Cache 7.x versions before 7.1.2 and 7.2.x versions before 7.2.1 are affected by CVE-2022-45059.
How can CVE-2022-45059 be mitigated?
To mitigate CVE-2022-45059, upgrade Varnish Cache to version 7.1.2 or 7.2.1.