CVE-2022-45060: Input Validation
An HTTP Request Forgery issue was discovered in Varnish Cache 5.x and 6.x before 6.0.11, 7.x before 7.1.2, and 7.2.x before 7.2.1. An attacker may introduce characters through HTTP/2 pseudo-headers that are invalid in the context of an HTTP/1 request line, causing the Varnish server to produce invalid HTTP/1 requests to the backend. This could, in turn, be used to exploit vulnerabilities in a server behind the Varnish server. Note: the 6.0.x LTS series (before 6.0.11) is affected.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/varnishto a version that resolves this vulnerability.Fixed in 7.1.1-1.1Fixed in 6.5.1-1+deb11u3 - Upgrade
Upgrade
debian/varnishto a version that resolves this vulnerability.Fixed in 6.5.1-1+deb11u3Fixed in 7.1.1-1.1Fixed in 7.7.0-1 - Upgrade
Upgrade
varnish-cacheto a version that resolves this vulnerability.Fixed in 6.0.11 - Upgrade
Upgrade
varnish-cacheto a version that resolves this vulnerability.Fixed in 7.1.2 - Upgrade
Upgrade
varnish-cacheto a version that resolves this vulnerability.Fixed in 7.2.1
Event History
Frequently Asked Questions
What is the severity of CVE-2022-45060?
The severity of CVE-2022-45060 is not explicitly specified, but it involves an HTTP Request Forgery vulnerability which can lead to significant security risks.
How do I fix CVE-2022-45060?
To fix CVE-2022-45060, upgrade to Varnish Cache versions 6.0.11 or higher, 6.5.1-1+deb11u3 or higher, and 7.1.1-1.1 or higher.
Which versions of Varnish Cache are affected by CVE-2022-45060?
CVE-2022-45060 affects Varnish Cache versions 5.x, 6.x before 6.0.11, 7.x before 7.1.2, and 7.2.x before 7.2.1.
Is my Varnish Cache installation vulnerable if I am using version 6.0.10?
Yes, Varnish Cache version 6.0.10 is vulnerable to CVE-2022-45060 and should be upgraded to a patched version.
What type of vulnerability is CVE-2022-45060?
CVE-2022-45060 is identified as an HTTP Request Forgery vulnerability.