CVE-2022-45060 is an HTTP Request Forgery vulnerability affecting Varnish Cache versions 5.x, 6.x (before 6.0.11), 7.x (before 7.1.2), and 7.2.x (before 7.2.1). An attacker can manipulate HTTP/2 pseudo-headers to inject invalid characters into HTTP/1 requests sent to backend servers, potentially exploiting vulnerabilities in those downstream systems. Rated 7.5 HIGH on CVSS, this vulnerability has a low attack complexity and can lead to high integrity impacts on backend services. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 6.0.0, < 6.0.11CPE matchmatch criteria | cpe:2.3:a:varnish-software:varnish_cache:*:*:*:*:lts:*:*:* | ||
6.0.0CPE matchmatch criteria | cpe:2.3:a:varnish-software:varnish_cache_plus:6.0.0:-:*:*:*:*:*:* | ||
6.0.0CPE matchmatch criteria | cpe:2.3:a:varnish-software:varnish_cache_plus:6.0.0:r0:*:*:*:*:*:* | ||
6.0.0CPE matchmatch criteria | cpe:2.3:a:varnish-software:varnish_cache_plus:6.0.0:r1:*:*:*:*:*:* | ||
6.0.0CPE matchmatch criteria | cpe:2.3:a:varnish-software:varnish_cache_plus:6.0.0:r2:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.