CVE-2022-45060

HIGHCVSS 7.5/10EPSS 0.93%

Last modified

CVE-2022-45060 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. An HTTP Request Forgery issue was discovered in Varnish Cache 5.x and 6.x before 6.0.11, 7.x before 7.1.2, and 7.2.x before 7.2.1. An attacker may introduce characters through HTTP/2 pseudo-headers that are invalid in the context of an HTTP/1 request line, causing the Varnish server to produce invalid HTTP/1 requests to the backend. EPSS estimates a 0.93% chance of exploitation in the next 30 days.

Description

An HTTP Request Forgery issue was discovered in Varnish Cache 5.x and 6.x before 6.0.11, 7.x before 7.1.2, and 7.2.x before 7.2.1. An attacker may introduce characters through HTTP/2 pseudo-headers that are invalid in the context of an HTTP/1 request line, causing the Varnish server to produce invalid HTTP/1 requests to the backend. This could, in turn, be used to exploit vulnerabilities in a server behind the Varnish server. Note: the 6.0.x LTS series (before 6.0.11) is affected.

Metrics

CVSS 3.1
7.5/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

EPSS Probability
0.93%

56.0th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersionsUpdate
Varnish-SoftwareVarnish Cache>= 6.0.0, < 6.0.11
Varnish-SoftwareVarnish Cache Plus6.0.0
Varnish-SoftwareVarnish Cache Plus6.0.1R1
Varnish-SoftwareVarnish Cache Plus6.0.2R1
Varnish-SoftwareVarnish Cache Plus6.0.3R1
Varnish-SoftwareVarnish Cache Plus6.0.4R1
Varnish-SoftwareVarnish Cache Plus6.0.5R1
Varnish-SoftwareVarnish Cache Plus6.0.6R1
Varnish-SoftwareVarnish Cache Plus6.0.7R1
Varnish-SoftwareVarnish Cache Plus6.0.8R1
Varnish-SoftwareVarnish Cache Plus6.0.9R1
Varnish-SoftwareVarnish Cache Plus6.0.10R1
Varnish Cache ProjectVarnish Cache>= 5.0.0, < 6.0.11
Varnish Cache ProjectVarnish Cache>= 7.0.0, < 7.1.2
Varnish Cache ProjectVarnish Cache7.2.0
FedoraprojectFedora35
FedoraprojectFedora36
FedoraprojectFedora37
DebianDebian Linux10.0
DebianDebian Linux11.0

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2022-45060?
An HTTP Request Forgery issue was discovered in Varnish Cache 5.x and 6.x before 6.0.11, 7.x before 7.1.2, and 7.2.x before 7.2.1. An attacker may introduce characters through HTTP/2 pseudo-headers that are invalid in the context of an HTTP/1 request line, causing the Varnish server to produce invalid HTTP/1 requests to the backend. This could, in turn, be used to exploit vulnerabilities in a server behind the Varnish server. Note: the 6.0.x LTS series (before 6.0.11) is affected.
How severe is CVE-2022-45060?
CVE-2022-45060 has a CVSS score of 7.5/10 (HIGH severity). The EPSS model estimates a 0.93% probability of exploitation in the next 30 days.
How do I fix CVE-2022-45060?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2022-45060?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST