PT-2025-12402 · Varnish · Varnish Enterprise

Published

2025-03-21

·

Updated

2025-03-21

·

CVE-2025-30347

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Varnish Enterprise versions prior to 6.0.13r13
Description The issue allows remote attackers to obtain sensitive information via an out-of-bounds read for range requests on ephemeral MSE4 stevedore objects.
Recommendations For versions prior to 6.0.13r13, update to version 6.0.13r13 or later to resolve the issue.

Fix

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-30347

Affected Products

Varnish Enterprise