Remote Code Injection Vulnerability in Varnish by Varnish Software
CVE-2015-8852
7.5HIGH
What is CVE-2015-8852?
In Varnish 3.x prior to version 3.0.7, a vulnerability exists that allows remote attackers to exploit certain setups. By sending a specially crafted HTTP request featuring multiple Content-Length headers along with a header line terminated by a carriage return character, attackers can inject arbitrary HTTP headers. This misuse can result in HTTP response splitting attacks, leading to further security risks within the affected system.
