Lucene search

K
redhatRedHatRHSA-2022:0418
HistoryFeb 03, 2022 - 9:29 a.m.

(RHSA-2022:0418) Important: varnish:6 security update

2022-02-0309:29:24
access.redhat.com
23
varnish cache
http accelerator
security update

CVSS2

6.4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:P/A:N

CVSS3

9.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

EPSS

0.005

Percentile

77.6%

Varnish Cache is a high-performance HTTP accelerator. It stores web pages in memory so web servers don’t have to create the same web page over and over again, giving the website a significant speed up.

Security Fix(es):

  • varnish: HTTP/1 request smuggling vulnerability (CVE-2022-23959)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

OSVersionArchitecturePackageVersionFilename
RedHatanyppc64levarnish-modules-debuginfo< 0.15.0-6.module+el8.5.0+11976+0b4af72dvarnish-modules-debuginfo-0.15.0-6.module+el8.5.0+11976+0b4af72d.ppc64le.rpm
RedHatanyppc64levarnish-modules-debugsource< 0.15.0-6.module+el8.5.0+11976+0b4af72dvarnish-modules-debugsource-0.15.0-6.module+el8.5.0+11976+0b4af72d.ppc64le.rpm
RedHatanyaarch64varnish-docs< 6.0.8-1.module+el8.5.0+14089+03a0c2cc.1varnish-docs-6.0.8-1.module+el8.5.0+14089+03a0c2cc.1.aarch64.rpm
RedHatanyppc64levarnish-modules< 0.15.0-6.module+el8.5.0+11976+0b4af72dvarnish-modules-0.15.0-6.module+el8.5.0+11976+0b4af72d.ppc64le.rpm
RedHatanyx86_64varnish-modules-debugsource< 0.15.0-6.module+el8.5.0+11976+0b4af72dvarnish-modules-debugsource-0.15.0-6.module+el8.5.0+11976+0b4af72d.x86_64.rpm
RedHatanyaarch64varnish< 6.0.8-1.module+el8.5.0+14089+03a0c2cc.1varnish-6.0.8-1.module+el8.5.0+14089+03a0c2cc.1.aarch64.rpm
RedHatanyx86_64varnish-docs< 6.0.8-1.module+el8.5.0+14089+03a0c2cc.1varnish-docs-6.0.8-1.module+el8.5.0+14089+03a0c2cc.1.x86_64.rpm
RedHatanyppc64levarnish-devel< 6.0.8-1.module+el8.5.0+14089+03a0c2cc.1varnish-devel-6.0.8-1.module+el8.5.0+14089+03a0c2cc.1.ppc64le.rpm
RedHatanyx86_64varnish-modules-debuginfo< 0.15.0-6.module+el8.5.0+11976+0b4af72dvarnish-modules-debuginfo-0.15.0-6.module+el8.5.0+11976+0b4af72d.x86_64.rpm
RedHatanys390xvarnish-modules-debugsource< 0.15.0-6.module+el8.5.0+11976+0b4af72dvarnish-modules-debugsource-0.15.0-6.module+el8.5.0+11976+0b4af72d.s390x.rpm
Rows per page:
1-10 of 241

CVSS2

6.4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:P/A:N

CVSS3

9.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

EPSS

0.005

Percentile

77.6%