CVE-2021-36740
14.07.2021, 17:15
Varnish Cache, with HTTP/2 enabled, allows request smuggling and VCL authorization bypass via a large Content-Length header for a POST request. This affects Varnish Enterprise 6.0.x before 6.0.8r3, and Varnish Cache 5.x and 6.x before 6.5.2, 6.6.x before 6.6.1, and 6.0 LTS before 6.0.8.
Vendor | Product | Version |
---|---|---|
varnish-cache | varnish_cache | 6.0.0 ≤ 𝑥 < 6.0.8 |
varnish-cache | varnish_cache | 6.0.8:r1 |
varnish-cache | varnish_cache | 6.0.8:r2 |
varnish-software | varnish_cache | 6.0.0 ≤ 𝑥 ≤ 6.0.5 |
varnish-software | varnish_cache | 6.0.0 ≤ 𝑥 ≤ 6.0.7 |
varnish_cache_project | varnish_cache | 5.0.0 ≤ 𝑥 ≤ 5.2.1 |
varnish_cache_project | varnish_cache | 6.1.0 ≤ 𝑥 ≤ 6.6.0 |
debian | debian_linux | 10.0 |
debian | debian_linux | 11.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
References