In Varnish Cache before 6.6.2 and 7.x before 7.0.2, Varnish Cache 6.0 LTS before 6.0.10, and and Varnish Enterprise (Cache Plus) 4.1.x before 4.1.11r6 and 6.0.x before 6.0.9r4, request smuggling can occur for HTTP/1 connections.
2022-01-26T01:15:07.900
2024-11-21T06:49:32.090
Modified
CVSSv3.1: 9.1 (CRITICAL)
AV:N/AC:L/Au:N/C:P/I:P/A:N
10.0
4.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | varnish-software | varnich_cache | < 6.6.2 | Yes |
Application | varnish-software | varnich_cache | < 4.1.11r6 | Yes |
Application | varnish-software | varnich_cache | 4.1 | Yes |
Application | varnish-software | varnish_cache | < 6.0.10 | Yes |
Application | varnish-software | varnish_cache_plus | < 6.0.9r4 | Yes |
Application | varnish_cache_project | varnish_cache | < 7.0.2 | Yes |
Operating System | fedoraproject | fedora | 35 | Yes |
Operating System | debian | debian_linux | 9.0 | Yes |
Operating System | debian | debian_linux | 10.0 | Yes |
Operating System | debian | debian_linux | 11.0 | Yes |