In Varnish Cache before 6.6.2 and 7.x before 7.0.2, Varnish Cache 6.0 LTS
before 6.0.10, and and Varnish Enterprise (Cache Plus) 4.1.x before
4.1.11r6 and 6.0.x before 6.0.9r4, request smuggling can occur for HTTP/1
connections. (CVE-2022-23959)
- https://bugs.mageia.org/show_bug.cgi?id=30048
- https://lists.debian.org/debian-lts-announce/2022/02/msg00014.html
- https://docs.varnish-software.com/security/VSV00008/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/UMMDMQWNAE3BTSZUHXQHVAMZC5TLHLYT/
- https://www.cve.org/CVERecord?id=CVE-2022-23959
- 8/core/varnish-6.5.1-1.2.mga8
Get the latest Linux and open source security news straight to your inbox.