An issue was discovered in Varnish Cache before 6.0.4 LTS, and 6.1.x and 6.2.x before 6.2.1. An HTTP/1 parsing failure allows a remote attacker to trigger an assert by sending crafted HTTP/1 requests. The assert will cause an automatic restart with a clean cache, which makes it a Denial of Service attack.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade varnish-modulesUpgrade varnish-docsUpgrade varnish-develUpgrade varnish | May 4, 2022 | Sep 3, 2019 |
| Alpine Linux | — | Upgrade varnish | Nov 8, 2019 | Sep 3, 2019 |
| Centos_linux | — | Upgrade varnish-modules-debuginfoUpgrade varnish-modules-debugsourceUpgrade varnish-develUpgrade varnish-docsUpgrade varnishUpgrade varnish-modules | Nov 5, 2020 | Sep 3, 2019 |
| Debian | — | Upgrade varnish | Sep 5, 2019 | Sep 3, 2019 |
| Oracle_linux | — | Upgrade varnish-docsUpgrade varnish-develUpgrade varnishUpgrade varnish-modules | Nov 12, 2020 | Sep 3, 2019 |
| Redhat_linux | — | Upgrade varnish-docsUpgrade varnish-modules-debuginfoUpgrade varnish-develUpgrade varnish-modulesUpgrade varnish-modules-debugsourceUpgrade varnish | Nov 5, 2020 | Sep 3, 2019 |
| Rocky_linux | — | Upgrade varnish-modulesUpgrade varnish-modules-debugsourceUpgrade varnishUpgrade varnish-modules-debuginfoUpgrade varnish-develUpgrade varnish-docs | Mar 12, 2024 | Sep 3, 2019 |
| Suse | — | Upgrade varnish-develUpgrade libvarnishapi2Upgrade varnish | Sep 26, 2019 | Sep 3, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub