Varnish Cache 7.x < 7.1.2 and 7.2.x < 7.2.1 - HTTP Request Smuggling via Hop-by-Hop Header Handling
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2022-45059. PoCs published by martinvks.
AI-analyzed exploit summary This repository demonstrates CVE-2022-45059, a request smuggling vulnerability in Varnish Cache versions 7.0.0-7.2.0. It includes a Spring Boot application behind a vulnerable Varnish instance to showcase cookie theft via hop-by-hop Content-Length header manipulation.
Description
An issue was discovered in Varnish Cache 7.x before 7.1.2 and 7.2.x before 7.2.1. A request smuggling attack can be performed on Varnish Cache servers by requesting that certain headers are made hop-by-hop, preventing the Varnish Cache servers from forwarding critical headers to the backend.
Exploits (1)
This repository demonstrates CVE-2022-45059, a request smuggling vulnerability in Varnish Cache versions 7.0.0-7.2.0. It includes a Spring Boot application behind a vulnerable Varnish instance to showcase cookie theft via hop-by-hop Content-Length header manipulation.
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N