Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Anthony Schwartz

#36680of 53,632
7.5Total CVSS
Vulnerabilities · 1
PT-2022-24243
7.5
2022-08-11
Unknown · Varnish Cache · CVE-2022-38150
**Name of the Vulnerable Software and Affected Versions** Varnish Cache versions 7.0.0 through 7.0.2 Varnish Cache version 7.1.0 **Description** The issue allows an attacker to cause the Varnish Server to assert and automatically restart through forged HTTP/1 backend responses. This is achieved by using a crafted reason phrase of the backend response status line. **Recommendations** For Varnish Cache versions 7.0.0 through 7.0.2, update to version 7.0.3 to resolve the issue. For Varnish Cache version 7.1.0, update to version 7.1.1 to resolve the issue.