[WID-SEC-2025-0585] Varnish HTTP Cache: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen CVSS Base Score 7.2 (hoch) CVSS Temporal Score 6.3 (mittel) Remoteangriff ja Datum 18.03.2025 Stand UPDATE 27.08.2026 Mitigation ja Betroffene Systeme Betriebssystem UNIX Produktbeschreibung Varnish ist ein Reverse-Proxy, der als HTTP-Beschleuniger verwendet wird. Produkte UPDATE 26.08.2026 Gentoo Linux UPDATE 15.04.2025 SUSE openSUSE UPDATE 31.03.2025 Debian Linux UPDATE 25.03.2025 Fedora Linux 18.03.2025 Open Source Varnish HTTP Cache <7.6.2 Open Source Varnish HTTP Cache <7.7.0 Angriff Angriff Ein Angreifer kann eine Schwachstelle in Varnish HTTP Cache ausnutzen, um Daten zu manipulieren, vertrauliche Informationen preiszugeben oder Sicherheitsmaßnahmen zu umgehen. CVE Informationen Versionshistorie Feedback zum Advisory geben
A vulnerability in Varnish HTTP Cache (CVSS 7.2) allows a remote attacker to manipulate data, disclose information, or bypass security measures. Affected versions are Varnish HTTP Cache versions prior to 7.6.2 and prior to 7.7.0. The article indicates mitigations are available but does not specify a fixed version or workaround.