CVE-2022-23959 is a critical request smuggling vulnerability (CWE-444) affecting Varnish Cache versions prior to 6.6.2, 7.0.2, 6.0.10, and specific Varnish Enterprise versions. This vulnerability allows attackers to manipulate HTTP/1 connections, potentially leading to unauthorized access to sensitive information (C) and data integrity compromise (I). With a CVSS score of 9.1 (CRITICAL), it is easily exploitable over the network with low attack complexity and no user interaction required. While there is no evidence of active exploitation, public exploit code, or Metasploit/Nuclei modules, the vulnerability has garnered significant community discussion, indicating awareness among security researchers.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.0.0, < 6.6.2CPE matchmatch criteria | cpe:2.3:a:varnish-software:varnich_cache:*:*:*:*:-:*:*:* | ||
>= 4.1.1, < 4.1.11r6CPE matchmatch criteria | cpe:2.3:a:varnish-software:varnich_cache:*:*:*:*:plus:*:*:* | ||
4.1CPE matchmatch criteria | cpe:2.3:a:varnish-software:varnich_cache:4.1:*:*:*:lts:*:*:* | ||
>= 6.0.0, < 6.0.10CPE matchmatch criteria | cpe:2.3:a:varnish-software:varnish_cache:*:*:*:*:lts:*:*:* | ||
>= 6.0.0, < 6.0.9r4CPE matchmatch criteria | cpe:2.3:a:varnish-software:varnish_cache_plus:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.