CVE-2021-36740

Published
View on NVD ↗
CVSS v3
6.5
MEDIUM
CVSS v2
6.4
MEDIUM
Affected
1
PROJECT

Description

Varnish Cache, with HTTP/2 enabled, allows request smuggling and VCL authorization bypass via a large Content-Length header for a POST request. This affects Varnish Enterprise 6.0.x before 6.0.8r3, and Varnish Cache 5.x and 6.x before 6.5.2, 6.6.x before 6.6.1, and 6.0 LTS before 6.0.8.

Varnish Cache source code repository
GitHubGitHub
4.05K