Server-Side Request Forgery (SSRF) in Varnish Cache and Varnish Enterprise - CVE-2022-45060
Published: November 8, 2022 / Updated: November 28, 2022
Vulnerability details
The disclosed vulnerability allows a remote attacker to perform SSRF attacks.
The vulnerability exists due to insufficient validation of user-supplied input when handling HTTP/2 requests. A remote attacker can introduce characters through the HTTP/2 pseudo-headers that are invalid in the context of an HTTP/1 request line, causing the Varnish server to produce invalid HTTP/1 requests to the backend.
Affected software
Varnish Enterprise
Oracle Linux
Debian Linux
Anolis OS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Ubuntu
openEuler
Fedora
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
libvarnishapi1 (Ubuntu package)
varnish (Ubuntu package)
libvarnishapi2 (Ubuntu package)
varnish-modules
varnish-docs
varnish-devel
varnish
rh-varnish6-varnish (Red Hat package)
varnish (Debian package)
varnish (Red Hat package)
varnish-help
varnish-debugsource
varnish-debuginfo
How to mitigate CVE-2022-45060
Varnish Enterprise - update to 6.0.10r3
libvarnishapi1 (Ubuntu package) - update to Ubuntu Pro
varnish (Ubuntu package) - update to Ubuntu Pro
libvarnishapi2 (Ubuntu package) - update to Ubuntu Pro
varnish-modules - update to 0.15.0-6
varnish-modules - update to 0.20.0-4.fc37
varnish-docs - update to 6.0.8-2
varnish-devel - update to 6.0.8-2
varnish - update to 6.0.8-2
rh-varnish6-varnish (Red Hat package) - update to 6.0.8-2.el7.2
varnish - addressed in versions 6.0-3520221118143100.f27b74a8, 6.0-3620221118143100.5e5ad4a0, 6.0-3720221118143100.9e842022, 6.6.2-3.fc35, 7.0.3-2.fc36, 7.1.2-1.fc37
varnish (Debian package) - update to 6.5.1-1+deb11u3
varnish (Red Hat package) - addressed in versions 6.6.2-2.el9_0.1, 6.6.2-2.el9_1.1
varnish-help - update to 7.0.1-7
varnish-debugsource - update to 7.0.1-7
varnish-devel - update to 7.0.1-7
varnish-debuginfo - update to 7.0.1-7
varnish - update to 7.0.1-7
External References
Related Security Bulletins
- Multiple vulnerabilities in Varnish Cache
- Red Hat Enterprise Linux 8.6 Extended Update Support update for the varnish:6 module
- Red Hat Enterprise Linux 8 update for the varnish:6 module
- Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions update for the varnish:6 module
- Red Hat Enterprise Linux 8 update for the varnish:6 module
- Red Hat Enterprise Linux 8.4 Extended Update Support update for the varnish:6 module
- Red Hat Enterprise Linux 9.0 Extended Update Support update for varnish
- Red Hat Enterprise Linux 9 update for varnish
- Debian update for varnish
- Red Hat Software Collections update for rh-varnish6-varnish
- Multiple vulnerabilities in Oracle Linux
- openEuler 22.03 LTS update for varnish
- Fedora 37 update for varnish, varnish-modules
- Fedora 36 update for varnish
- Fedora 35 update for varnish
- Fedora 36 Modular update for varnish
- Fedora 35 Modular update for varnish
- Fedora 37 Modular update for varnish
- Ubuntu update for varnish
- Anolis OS update for varnish:6 module