Server-Side Request Forgery (SSRF) in Varnish Cache and Varnish Enterprise - CVE-2022-45060

 

Server-Side Request Forgery (SSRF) in Varnish Cache and Varnish Enterprise - CVE-2022-45060

Published: November 8, 2022 / Updated: November 28, 2022


Vulnerability identifier: #VU69128
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:L/SI:N/SA:N]
CVE-ID: CVE-2022-45060
CWE-ID: CWE-918
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The disclosed vulnerability allows a remote attacker to perform SSRF attacks.

The vulnerability exists due to insufficient validation of user-supplied input when handling HTTP/2 requests. A remote attacker can introduce characters through the HTTP/2 pseudo-headers that are invalid in the context of an HTTP/1 request line, causing the Varnish server to produce invalid HTTP/1 requests to the backend.



Affected software

Varnish Cache
Varnish Enterprise
Oracle Linux
Debian Linux
Anolis OS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Ubuntu
openEuler
Fedora
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
libvarnishapi1 (Ubuntu package)
varnish (Ubuntu package)
libvarnishapi2 (Ubuntu package)
varnish-modules
varnish-docs
varnish-devel
varnish
rh-varnish6-varnish (Red Hat package)
varnish (Debian package)
varnish (Red Hat package)
varnish-help
varnish-debugsource
varnish-debuginfo

How to mitigate CVE-2022-45060

Install updates from vendor's website.

Varnish Cache - addressed in versions 6.0.11, 7.1.2, 7.2.1
Varnish Enterprise - update to 6.0.10r3
libvarnishapi1 (Ubuntu package) - update to Ubuntu Pro
varnish (Ubuntu package) - update to Ubuntu Pro
libvarnishapi2 (Ubuntu package) - update to Ubuntu Pro
varnish-modules - update to 0.15.0-6
varnish-modules - update to 0.20.0-4.fc37
varnish-docs - update to 6.0.8-2
varnish-devel - update to 6.0.8-2
varnish - update to 6.0.8-2
rh-varnish6-varnish (Red Hat package) - update to 6.0.8-2.el7.2
varnish - addressed in versions 6.0-3520221118143100.f27b74a8, 6.0-3620221118143100.5e5ad4a0, 6.0-3720221118143100.9e842022, 6.6.2-3.fc35, 7.0.3-2.fc36, 7.1.2-1.fc37
varnish (Debian package) - update to 6.5.1-1+deb11u3
varnish (Red Hat package) - addressed in versions 6.6.2-2.el9_0.1, 6.6.2-2.el9_1.1
varnish-help - update to 7.0.1-7
varnish-debugsource - update to 7.0.1-7
varnish-devel - update to 7.0.1-7
varnish-debuginfo - update to 7.0.1-7
varnish - update to 7.0.1-7

External References

Related Security Bulletins