An issue was discovered in Varnish Cache before 6.0.6 LTS, 6.1.x and 6.2.x before 6.2.3, and 6.3.x before 6.3.2. It occurs when communication with a TLS termination proxy uses PROXY version 2. There can be an assertion failure and daemon restart, which causes a performance loss.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade varnishUpgrade varnish-modulesUpgrade varnish-docsUpgrade varnish-devel | May 4, 2022 | Apr 8, 2020 |
| Centos_linux | — | Upgrade varnish-modules-debuginfoUpgrade varnish-modulesUpgrade varnish-develUpgrade varnish-docsUpgrade varnishUpgrade varnish-modules-debugsource | Nov 5, 2020 | Apr 8, 2020 |
| Debian | — | Upgrade varnish | Nov 29, 2022 | Apr 8, 2020 |
| Oracle_linux | — | Upgrade varnishUpgrade varnish-modulesUpgrade varnish-docsUpgrade varnish-devel | Nov 12, 2020 | Feb 4, 2020 |
| Redhat_linux | — | Upgrade varnish-modules-debugsourceUpgrade varnishUpgrade varnish-modules-debuginfoUpgrade varnish-develUpgrade varnish-modulesUpgrade varnish-docs | Nov 5, 2020 | Apr 8, 2020 |
| Rocky_linux | — | Upgrade varnishUpgrade varnish-modules-debuginfoUpgrade varnish-docsUpgrade varnish-modules-debugsourceUpgrade varnish-develUpgrade varnish-modules | Mar 12, 2024 | Apr 8, 2020 |
| Suse | — | Upgrade varnish-develUpgrade libvarnishapi2Upgrade varnish | Jun 16, 2020 | Apr 8, 2020 |
| Ubuntu | — | Upgrade libvarnishapi1Upgrade varnishUpgrade libvarnishapi2 | Jun 9, 2022 | Apr 8, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub