Varnish Enterprise before 6.0.13r13 allows remote attackers to obtain sensitive information via an out-of-bounds read for range requests on ephemeral MSE4 stevedore objects.
2025-03-21T07:15:37.527
2025-03-24T14:19:23.963
Analyzed
CVSSv3.1: 4.0 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | varnish-software | varnish_enterprise | 6.0.13 | Yes |
Application | varnish-software | varnish_enterprise | 6.0.13 | Yes |
Application | varnish-software | varnish_enterprise | 6.0.13 | Yes |
Application | varnish-software | varnish_enterprise | 6.0.13 | Yes |
Application | varnish-software | varnish_enterprise | 6.0.13 | Yes |
Application | varnish-software | varnish_enterprise | 6.0.13 | Yes |
Application | varnish-software | varnish_enterprise | 6.0.13 | Yes |
Application | varnish-software | varnish_enterprise | 6.0.13 | Yes |
Application | varnish-software | varnish_enterprise | 6.0.13 | Yes |
Application | varnish-software | varnish_enterprise | 6.0.13 | Yes |
Application | varnish-software | varnish_enterprise | 6.0.13 | Yes |