An issue was discovered in Varnish Cache before 6.0.6 LTS, 6.1.x and 6.2.x before 6.2.3, and 6.3.x before 6.3.2. It occurs when communication with a TLS termination proxy uses PROXY version 2. There can be an assertion failure and daemon restart, which causes a performance loss.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade varnish-docsUpgrade varnish-develUpgrade varnish-modulesUpgrade varnish | May 4, 2022 | Apr 8, 2020 |
| Centos_linux | — | Upgrade varnish-modules-debugsourceUpgrade varnishUpgrade varnish-docsUpgrade varnish-modulesUpgrade varnish-modules-debuginfoUpgrade varnish-devel | Nov 5, 2020 | Apr 8, 2020 |
| Debian | — | Upgrade varnish | Nov 29, 2022 | Apr 8, 2020 |
| Oracle_linux | — | Upgrade varnish-docsUpgrade varnish-develUpgrade varnishUpgrade varnish-modules | Nov 12, 2020 | Feb 4, 2020 |
| Redhat_linux | — | Upgrade varnishUpgrade varnish-modules-debugsourceUpgrade varnish-modulesUpgrade varnish-develUpgrade varnish-docsUpgrade varnish-modules-debuginfo | Nov 5, 2020 | Apr 8, 2020 |
| Rocky_linux | — | Upgrade varnish-modules-debugsourceUpgrade varnish-docsUpgrade varnish-modulesUpgrade varnish-develUpgrade varnish-modules-debuginfoUpgrade varnish | Mar 12, 2024 | Apr 8, 2020 |
| Suse | — | Upgrade varnishUpgrade varnish-develUpgrade libvarnishapi2 | Jun 16, 2020 | Apr 8, 2020 |
| Ubuntu | — | Upgrade varnishUpgrade libvarnishapi2Upgrade libvarnishapi1 | Jun 9, 2022 | Apr 8, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub