PT-2024-40272 · Ibexa+1 · Ibexa/Http-Cache+1

Published

2024-12-02

·

Updated

2024-12-02

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions: ibexa/http-cache (affected versions not specified)
Description: The issue is related to the BREACH vulnerability, which affects HTTP compression and can allow secrets to be extracted through carefully crafted requests. This is due to included Varnish VCL templates that enable compression of API and JSON messages. To mitigate this, it is recommended to disable compression in these templates and check web server configurations.
Recommendations: Disable HTTP compression for REST API requests and other communication that might contain secrets. Make sure to make the same change in your configuration files, following the specific instructions in the release notes. Check your web server configuration to ensure HTTP compression is disabled for sensitive data. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

GHSA-FH7V-Q458-7VMW

Affected Products

Varnish
Ibexa/Http-Cache