USN-5474-1
Dashboard / Vulnerabilities / USN-5474-1
USN-5474-1
Summary: varnish vulnerabilities
Details: It was dicovered that Varnish Cache did not clear a pointer between the handling of one client request and the next request within the same connection. A remote attacker could possibly use this issue to obtain sensitive information. (CVE-2019-20637) It was discovered that Varnish Cache could have an assertion failure when a TLS termination proxy uses PROXY version 2. A remote attacker could possibly use this issue to restart the daemon and cause a performance loss. (CVE-2020-11653) It was discovered that Varnish Cache allowed request smuggling and VCL authorization bypass via a large Content-Length header for a POST request. A remote attacker could possibly use this issue to obtain sensitive information. (CVE-2021-36740) It was discovered that Varnish Cache allowed request smuggling for HTTP/1 connections. A remote attacker could possibly use this issue to obtain sensitive information. (CVE-2022-23959)
References: https://ubuntu.com/security/notices/USN-5474-1, https://ubuntu.com/security/CVE-2019-20637, https://ubuntu.com/security/CVE-2020-11653, https://ubuntu.com/security/CVE-2021-36740, https://ubuntu.com/security/CVE-2022-23959
Affected packages
Package
Name: varnish
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=bionic
Affected ranges
Type: ECOSYSTEM
Events:
