Varnish Cache
cpe:2.3:a:varnish-cache:varnish:*:*:*:*:*:*:*, +2 more
- >= 6.0.0, <= 6.0.5
- >= 6.1.0, <= 6.1.1
- >= 6.2.0, <= 6.2.1
- >= 6.3.0, <= 6.3.1
A denial-of-service vulnerability has been identified in Varnish Cache versions prior to 6.0.6 LTS, 6.1.x, 6.2.x prior to 6.2.3, and 6.3.x prior to 6.3.2. The issue arises when Varnish communicates with a TLS termination proxy using PROXY version 2, leading to an assertion failure that causes the Varnish daemon to restart. This restart empties the cache, resulting in performance degradation and increased load on backend servers.
Exploitation of this vulnerability causes Varnish to assert and restart, emptying the cache and leading to performance losses due to increased cache misses. This may also cause higher load on backend servers.
Users can switch to proxy protocol version 1 if their TLS termination proxy supports it. For those using Hitch as the TLS proxy, non-matching SNI names can be disallowed, and the session workspace can be increased to mitigate the issue. Varnish Cache versions 6.2.3, 6.3.2, and 6.0.6 LTS by Varnish Software include the fix.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.