An issue was discovered in Varnish Cache before 6.0.4 LTS, and 6.1.x and 6.2.x before 6.2.1. An HTTP/1 parsing failure allows a remote attacker to trigger an assert by sending crafted HTTP/1 requests. The assert will cause an automatic restart with a clean cache, which makes it a Denial of Service attack.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade varnish-modulesUpgrade varnishUpgrade varnish-develUpgrade varnish-docs | May 4, 2022 | Sep 3, 2019 |
| Alpine Linux | — | Upgrade varnish | Nov 8, 2019 | Sep 3, 2019 |
| Centos_linux | — | Upgrade varnish-modules-debuginfoUpgrade varnish-modules-debugsourceUpgrade varnish-docsUpgrade varnishUpgrade varnish-develUpgrade varnish-modules | Nov 5, 2020 | Sep 3, 2019 |
| Debian | — | Upgrade varnish | Sep 5, 2019 | Sep 3, 2019 |
| Oracle_linux | — | Upgrade varnish-docsUpgrade varnish-develUpgrade varnish-modulesUpgrade varnish | Nov 12, 2020 | Sep 3, 2019 |
| Redhat_linux | — | Upgrade varnish-modules-debugsourceUpgrade varnishUpgrade varnish-modulesUpgrade varnish-docsUpgrade varnish-modules-debuginfoUpgrade varnish-devel | Nov 5, 2020 | Sep 3, 2019 |
| Rocky_linux | — | Upgrade varnishUpgrade varnish-modules-debugsourceUpgrade varnish-modulesUpgrade varnish-develUpgrade varnish-modules-debuginfoUpgrade varnish-docs | Mar 12, 2024 | Sep 3, 2019 |
| Suse | — | Upgrade varnish-develUpgrade libvarnishapi2Upgrade varnish | Sep 26, 2019 | Sep 3, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub