Varnish Cache/Enterprise prior LTS 6.0.8/6.0.8r3/6.5.2/6.6.1 HTTP2 request smuggling

A vulnerability was found in Varnish Cache and Enterprise. It has been declared as critical. This vulnerability affects some unknown processing of the component HTTP2 Handler. Upgrading to version LTS 6.0.8, 6.0.8r3, 6.5.2 or 6.6.1 eliminates this vulnerability. Applying a patch is able to eliminate this problem. The bugfix is ready for download at github.com. The best possible mitigation is suggested to be upgrading to the latest version.

Common Vulnerabilityies and Exposures

Contact us to get started

CVE-2024-5618 : PRUVASOFT INFORMATICS APINIZER MANAGEMENT CONSOLE PRIOR 2024.05.1 PERMISSION ASSIGNMENT

CVE-2024-5618 : PRUVASOFT INFORMATICS APINIZER MANAGEMENT CONSOLE PRIOR 2024.05.1 PERMISSION ASSIGNMENT

Description Incorrect Permission Assignment for Critical Resource vulnerability in PruvaSoft Informatics Apinizer Management Console allows Accessing Functionality Not Properly Constrained

CVE-2024-39907 : 1PANEL 1.10.9-TLS/1.10.10-TLS/1.10.11-TLS SQL INJECTION

CVE-2024-39907 : 1PANEL 1.10.9-TLS/1.10.10-TLS/1.10.11-TLS SQL INJECTION

Description 1Panel is a web-based linux server management control panel. There are many sql injections in the project, and some

CVE-2024-20401 : CISCO SECURE EMAIL CONTENT SCANNING/MESSAGE FILTERING ABSOLUTE PATH TRAVERSAL

CVE-2024-20401 : CISCO SECURE EMAIL CONTENT SCANNING/MESSAGE FILTERING ABSOLUTE PATH TRAVERSAL

Description A vulnerability in the content scanning and message filtering features of Cisco Secure Email Gateway could allow an unauthenticated,