Request Smuggling Vulnerability in Varnish Cache by Varnish Software
CVE-2022-45059

7.5HIGH

Key Information:

Vendor
CVE Published:
9 November 2022

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2022-45059?

A vulnerability exists in Varnish Cache that allows for request smuggling attacks. This issue affects versions 7.x prior to 7.1.2 and 7.2.x prior to 7.2.1. Attackers can exploit the vulnerability by manipulating specific headers. These headers can be made hop-by-hop in transit, preventing the Varnish Cache servers from forwarding critical information to backend systems. This may lead to unauthorized access or data manipulation, compromising the integrity of the caching mechanism.

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.