Home
MEDIUM: 4.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:NDefault status
unaffected
6 (custom) before 6.0.13r13
affected
Description
Varnish Enterprise before 6.0.13r13 allows remote attackers to obtain sensitive information via an out-of-bounds read for range requests on ephemeral MSE4 stevedore objects.
Problem types
Product status
6 (custom) before 6.0.13r13
References
docs.varnish-software.com/security/VEV00001/