libvmod-digest before 1.0.3, as used in Varnish Enterprise 6.0.x before 6.0.11r5, has an out-of-bounds memory access during base64 decoding, leading to both authentication bypass and information disclosure; however, the exact attack surface will depend on the particular VCL (Varnish Configuration Language) configuration in use.
2023-08-23T07:15:08.417
2024-11-21T08:20:35.543
Modified
CVSSv3.1: 6.5 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | varnish-software | varnish_enterprise | < 6.0.11 | Yes |
Application | varnish-software | varnish_enterprise | 6.0.11 | Yes |
Application | varnish-software | varnish_enterprise | 6.0.11 | Yes |
Application | varnish-software | varnish_enterprise | 6.0.11 | Yes |
Application | varnish-software | varnish_enterprise | 6.0.11 | Yes |
Application | varnish-software | varnish_enterprise | 6.0.11 | Yes |
Application | varnish-software | vmod_digest | < 1.0.3 | Yes |