Filtered by vendor Varnish-software
Subscriptions
Filtered by product Varnish Enterprise
Subscriptions
Total
1 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2023-41104 | 2 Libvmod Digest, Varnish-software | 3 Libvmod Digest, Varnish Enterprise, Vmod Digest | 2024-10-03 | 6.5 Medium |
libvmod-digest before 1.0.3, as used in Varnish Enterprise 6.0.x before 6.0.11r5, has an out-of-bounds memory access during base64 decoding, leading to both authentication bypass and information disclosure; however, the exact attack surface will depend on the particular VCL (Varnish Configuration Language) configuration in use. |
Page 1 of 1.