CVE-2023-41104
23.08.2023, 07:15
libvmod-digest before 1.0.3, as used in Varnish Enterprise 6.0.x before 6.0.11r5, has an out-of-bounds memory access during base64 decoding, leading to both authentication bypass and information disclosure; however, the exact attack surface will depend on the particular VCL (Varnish Configuration Language) configuration in use.Enginsight
Vendor | Product | Version |
---|---|---|
varnish-software | varnish_enterprise | 6.0.0 ≤ 𝑥 < 6.0.11 |
varnish-software | varnish_enterprise | 6.0.11 |
varnish-software | varnish_enterprise | 6.0.11:r1 |
varnish-software | varnish_enterprise | 6.0.11:r2 |
varnish-software | varnish_enterprise | 6.0.11:r3 |
varnish-software | varnish_enterprise | 6.0.11:r4 |
varnish-software | vmod_digest | 𝑥 < 1.0.3 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References