CVE-2020-11653: High severity varnish cache vulnerability
An issue was discovered in Varnish Cache before 6.0.6 LTS, 6.1.x and 6.2.x before 6.2.3, and 6.3.x before 6.3.2. It occurs when communication with a TLS termination proxy uses PROXY version 2. There can be an assertion failure and daemon restart, which causes a performance loss.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-11653?
CVE-2020-11653 is a vulnerability in Varnish Cache that occurs when communication with a TLS termination proxy uses PROXY version 2, leading to an assertion failure and daemon restart.
What software is affected by CVE-2020-11653?
Varnish Cache versions 6.0.0 to 6.0.6 LTS, 6.1.x, 6.2.x, and 6.3.0 to 6.3.2 are affected by CVE-2020-11653.
What is the severity of CVE-2020-11653?
CVE-2020-11653 has a severity level of high with a CVSS score of 7.5.
How can I fix CVE-2020-11653?
To fix CVE-2020-11653, upgrade to Varnish Cache version 6.0.6 LTS, 6.2.3, or 6.3.2.
Where can I find more information about CVE-2020-11653?
More information about CVE-2020-11653 can be found at the following references: [1], [2], [3].