Vulnerabilities (CVE)

Filtered by vendor Varnish-software Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-41104 1 Varnish-software 2 Varnish Enterprise, Vmod Digest 2023-08-28 N/A 6.5 MEDIUM
libvmod-digest before 1.0.3, as used in Varnish Enterprise 6.0.x before 6.0.11r5, has an out-of-bounds memory access during base64 decoding, leading to both authentication bypass and information disclosure; however, the exact attack surface will depend on the particular VCL (Varnish Configuration Language) configuration in use.
CVE-2022-23959 1 Varnish-software 1 Varnich Cache 2022-02-16 6.4 MEDIUM 9.1 CRITICAL
In Varnish Cache before 6.6.2 and 7.x before 7.0.2, Varnish Cache 6.0 LTS before 6.0.10, and and Varnish Enterprise (Cache Plus) 4.1.x before 4.1.11r6 and 6.0.x before 6.0.9r4, request smuggling can occur for HTTP/1 connections.