Request Smuggling Vulnerability in Varnish Cache by Varnish Software
CVE-2022-45059
7.5HIGH
Key Information:
- Vendor
Varnish Cache Project
- Status
- Vendor
- CVE Published:
- 9 November 2022
Badges
๐พ Exploit Exists๐ก Public PoC
What is CVE-2022-45059?
A vulnerability exists in Varnish Cache that allows for request smuggling attacks. This issue affects versions 7.x prior to 7.1.2 and 7.2.x prior to 7.2.1. Attackers can exploit the vulnerability by manipulating specific headers. These headers can be made hop-by-hop in transit, preventing the Varnish Cache servers from forwarding critical information to backend systems. This may lead to unauthorized access or data manipulation, compromising the integrity of the caching mechanism.
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
