RHSA-2024:1690: Important: varnish security update
Important: varnish security update
Other sources
Varnish Cache is a high-performance HTTP accelerator. It stores web pages in memory so web servers don't have to create the same web page over and over again, giving the website a significant speed up.<br>Security Fix(es):<br><li> varnish: HTTP/2 Broken Window Attack may result in denial of service (CVE-2024-30156)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:1690?
The severity of RHSA-2024:1690 is classified as important.
What vulnerabilities are addressed in RHSA-2024:1690?
RHSA-2024:1690 addresses vulnerabilities related to HTTP/2 in Varnish Cache.
How do I fix RHSA-2024:1690?
To fix RHSA-2024:1690, you should update to the corrected packages provided in the advisory.
Which versions of Varnish are affected by RHSA-2024:1690?
Versions of Varnish prior to 6.0.13-1.module+el8.9.0+21617+7578fa11 are affected by RHSA-2024:1690.
What is Varnish Cache and why is it important?
Varnish Cache is a high-performance HTTP accelerator that significantly increases website speed by caching web pages in memory.