Description


Varnish Cache, with HTTP/2 enabled, allows request smuggling and VCL authorization bypass via a large Content-Length header for a POST request. This affects Varnish Enterprise 6.0.x before 6.0.8r3, and Varnish Cache 5.x and 6.x before 6.5.2, 6.6.x before 6.6.1, and 6.0 LTS before 6.0.8.

Related CPE's


a

varnish-cache

varnish_cache

3

a

varnish-software

varnish_cache

2

a

varnish_cache_project

varnish_cache

2

o

fedoraproject

fedora

2

o

debian

debian_linux

2

Weaknesses



CWE-444

CVSS impact metrics


CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

6.5 · Medium

  • CVSS V3.1

  • CVSS V3.0

  • CVSS V2.0

Information


Source identifier

[email protected]

Vulnerability status

Modified

Published

2021-07-14T17:15:08.253

3 years ago

Last modified

2023-11-07T03:36:47.880

1 year ago