Out-of-Bounds Memory Access in libvmod-digest for Varnish Enterprise
CVE-2023-41104

6.5MEDIUM

Key Information:

Vendor
CVE Published:
23 August 2023

What is CVE-2023-41104?

The vulnerability in libvmod-digest allows for an out-of-bounds memory access during base64 decoding. This issue, present in versions prior to 1.0.3, can lead to both authentication bypass and information disclosure. The potential impact of the vulnerability is influenced by the specific configuration of Varnish Configuration Language (VCL) in use, making certain configurations more susceptible to exploitation. It is advisable for users of Varnish Enterprise 6.0.x to review their VCL settings and upgrade to the patched version to mitigate this risk.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.