CVE-2015-8852
Last modified
CVE-2015-8852 is a vulnerability of currently unknown severity. Varnish 3.x before 3.0.7, when used in certain stacked installations, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a header line terminated by a \r (carriage return) character in conjunction with multiple Content-Length headers in an HTTP request.. EPSS estimates a 3.43% chance of exploitation in the next 30 days.
Description
Varnish 3.x before 3.0.7, when used in certain stacked installations, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a header line terminated by a \r (carriage return) character in conjunction with multiple Content-Length headers in an HTTP request.
Metrics
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Varnish Cache Project | Varnish Cache | 3.0.0 | Beta1 |
| Varnish Cache Project | Varnish Cache | 3.0.1 | — |
| Varnish Cache Project | Varnish Cache | 3.0.2 | — |
| Varnish Cache Project | Varnish Cache | 3.0.3 | — |
| Varnish Cache Project | Varnish Cache | 3.0.4 | — |
| Varnish Cache Project | Varnish Cache | 3.0.5 | — |
| Varnish Cache Project | Varnish Cache | 3.0.6 | — |
| Debian | Debian Linux | 7.0 | — |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2015-8852?
How severe is CVE-2015-8852?
How do I fix CVE-2015-8852?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2015
- CVE-2015-8841Heap-based buffer overflow in the Archive support module in …9.8
- CVE-2015-8842tmpfiles.d/systemd.conf in systemd before 229 uses weak perm…
- CVE-2015-8843The Foxit Cloud Update Service (FoxitCloudUpdateService) in …
- CVE-2015-8844The signal implementation in the Linux kernel before 4.3.5 o…
- CVE-2015-8845The tm_reclaim_thread function in arch/powerpc/kernel/proces…
- CVE-2015-8851node-uuid before 1.4.4 uses insufficiently random data to cr…7.5
- CVE-2015-8853The (1) S_reghop3, (2) S_reghop4, and (3) S_reghopmaybe3 fun…
- CVE-2015-8854The marked package before 0.3.4 for Node.js allows attackers…7.5
- CVE-2015-8855The semver package before 4.3.2 for Node.js allows attackers…
- CVE-2015-8856Cross-site scripting (XSS) vulnerability in the serve-index …6.1
- CVE-2015-8857The uglify-js package before 2.4.24 for Node.js does not pro…9.8
- CVE-2015-8858The uglify-js package before 2.6.0 for Node.js allows attack…
Are you affected by CVE-2015-8852?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
