An issue was discovered in Varnish Cache before 6.0.4 LTS, and 6.1.x and 6.2.x before 6.2.1. An HTTP/1 parsing failure allows a remote attacker to trigger an assert by sending crafted HTTP/1 requests. The assert will cause an automatic restart with a clean cache, which makes it a Denial of Service attack.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade varnish-docsUpgrade varnishUpgrade varnish-develUpgrade varnish-modules | May 4, 2022 | Sep 3, 2019 |
| Alpine Linux | — | Upgrade varnish | Nov 8, 2019 | Sep 3, 2019 |
| Centos_linux | — | Upgrade varnish-modules-debugsourceUpgrade varnish-modules-debuginfoUpgrade varnish-develUpgrade varnish-docsUpgrade varnish-modulesUpgrade varnish | Nov 5, 2020 | Sep 3, 2019 |
| Debian | — | Upgrade varnish | Sep 5, 2019 | Sep 3, 2019 |
| Oracle_linux | — | Upgrade varnishUpgrade varnish-modulesUpgrade varnish-docsUpgrade varnish-devel | Nov 12, 2020 | Sep 3, 2019 |
| Redhat_linux | — | Upgrade varnish-modules-debuginfoUpgrade varnish-develUpgrade varnish-docsUpgrade varnishUpgrade varnish-modulesUpgrade varnish-modules-debugsource | Nov 5, 2020 | Sep 3, 2019 |
| Rocky_linux | — | Upgrade varnish-develUpgrade varnish-docsUpgrade varnish-modules-debuginfoUpgrade varnish-modulesUpgrade varnish-modules-debugsourceUpgrade varnish | Mar 12, 2024 | Sep 3, 2019 |
| Suse | — | Upgrade varnishUpgrade varnish-develUpgrade libvarnishapi2 | Sep 26, 2019 | Sep 3, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub