PT-2021-21330 · Varnish+5 · Varnish Enterprise+6
Martin Blix Grydeland
·
Published
2021-07-14
·
Updated
2024-03-06
·
CVE-2021-36740
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Varnish Enterprise versions 6.0.x through 6.0.8r2
Varnish Cache versions 5.x through 6.5.1
Varnish Cache versions 6.6.x through 6.6.0
Varnish Cache 6.0 LTS versions prior to 6.0.8
Description
The issue allows request smuggling and VCL authorization bypass via a large Content-Length header for a POST request when HTTP/2 is enabled.
Recommendations
For Varnish Enterprise versions 6.0.x through 6.0.8r2, update to version 6.0.8r3 or later.
For Varnish Cache versions 5.x through 6.5.1, update to version 6.5.2 or later.
For Varnish Cache versions 6.6.x through 6.6.0, update to version 6.6.1 or later.
For Varnish Cache 6.0 LTS versions prior to 6.0.8, update to version 6.0.8 or later.
Fix
HTTP Request/Response Smuggling
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Centos
Linuxmint
Red Hat
Rocky Linux
Ubuntu
Varnish Cache
Varnish Enterprise