kube-httpcache is vulnerable to Cross-Site Request Forgery (CSRF)
Moderate severity
GitHub Reviewed
Published
Nov 29, 2022
in
mittwald/kube-httpcache
•
Updated Jan 12, 2023
Description
Published to the GitHub Advisory Database
Dec 2, 2022
Reviewed
Dec 2, 2022
Last updated
Jan 12, 2023
Impact
Patches
This is fixed in Varnish 6.0.11; Varnish 6.0.11 is available in
kube-httpcache
versions v0.7.1 and later.Workarounds
See upstream mitigation hints.
References
References