CVE-2023-41104
23.08.2023, 07:15
libvmod-digest before 1.0.3, as used in Varnish Enterprise 6.0.x before 6.0.11r5, has an out-of-bounds memory access during base64 decoding, leading to both authentication bypass and information disclosure; however, the exact attack surface will depend on the particular VCL (Varnish Configuration Language) configuration in use.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| varnish-software | varnish_enterprise | 6.0.0 ≤ 𝑥 < 6.0.11 |
| varnish-software | varnish_enterprise | 6.0.11 |
| varnish-software | varnish_enterprise | 6.0.11:r1 |
| varnish-software | varnish_enterprise | 6.0.11:r2 |
| varnish-software | varnish_enterprise | 6.0.11:r3 |
| varnish-software | varnish_enterprise | 6.0.11:r4 |
| varnish-software | vmod_digest | 𝑥 < 1.0.3 |
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| libvmod_digest | libvmod_digest | 𝑥 < 1.0.3 | ADP |
| libvmod_digest | libvmod_digest | varnish_enterprise_6.0x ≤ 𝑥 < 6.0.11r5 | ADP |
Common Weakness Enumeration
References