varnish: HTTP/2 request smuggling attack via a large Content-Length header for a POST request
Published Jul 14, 2021
8.1
HIGHCVSS 3.1
EPSS 1.60%
Description
Varnish Cache, with HTTP/2 enabled, allows request smuggling and VCL authorization bypass via a large Content-Length header for a POST request. This affects Varnish Enterprise 6.0.x before 6.0.8r3, and Varnish Cache 5.x and 6.x before 6.5.2, 6.6.x before 6.6.1, and 6.0 LTS before 6.0.8.
Affected products
No data.
Configuration 1
- ≥ 6.0.0 · < 6.0.8
- 6.0.8
- 6.0.8
- ≥ 6.0.0 · ≤ 6.0.5
- ≥ 6.0.0 · ≤ 6.0.7
- ≥ 5.0.0 · ≤ 5.2.1
- ≥ 6.1.0 · ≤ 6.6.0
Configuration 2
- 33
- 34
Configuration 3
- 10.0
- 11.0
No data.
Red Hat Enterprise Linux 8
varnish:6-8040020210722190209.522a0ee4
Fixed · RHSA-2021:2988
Red Hat Enterprise Linux 8.1 Extended Update Support
varnish:6-8010020210726155835.c27ad7f8
Fixed · RHSA-2021:2988
Red Hat Enterprise Linux 8.2 Extended Update Support
varnish:6-8020020210726155330.4cda2c84
Fixed · RHSA-2021:2988
Red Hat Software Collections for Red Hat Enterprise Linux 7
rh-varnish6-varnish-0:6.0.8-2.el7
Fixed · RHSA-2021:2993
Red Hat Software Collections for Red Hat Enterprise Linux 7
rh-varnish6-varnish-modules-0:0.15.0-7.el7
Fixed · RHSA-2021:2993
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS
rh-varnish6-varnish-0:6.0.8-2.el7
Fixed · RHSA-2021:2993
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS
rh-varnish6-varnish-modules-0:0.15.0-7.el7
Fixed · RHSA-2021:2993
Red Hat Enterprise Linux 9
varnish
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | varnish:6-8040020210722190209.522a0ee4 | Fixed | RHSA-2021:2988 |
| Red Hat Enterprise Linux 8.1 Extended Update Support | varnish:6-8010020210726155835.c27ad7f8 | Fixed | RHSA-2021:2988 |
| Red Hat Enterprise Linux 8.2 Extended Update Support | varnish:6-8020020210726155330.4cda2c84 | Fixed | RHSA-2021:2988 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-varnish6-varnish-0:6.0.8-2.el7 | Fixed | RHSA-2021:2993 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-varnish6-varnish-modules-0:0.15.0-7.el7 | Fixed | RHSA-2021:2993 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS | rh-varnish6-varnish-0:6.0.8-2.el7 | Fixed | RHSA-2021:2993 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS | rh-varnish6-varnish-modules-0:0.15.0-7.el7 | Fixed | RHSA-2021:2993 |
| Red Hat Enterprise Linux 9 | varnish | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
This issue can be mitigated by: 1) Disabling HTTP/2 request support by executing: ~~~ sudo varnishadm param.set feature -http2 ~~~ 2) Disabling backend connection reuse on varnish side, the following rule can be inserted into Varnish configuration: ~~~ sub vcl_backend_fetch { set bereq.http.Connection = "close"; } ~~~
References (11)
- https://access.redhat.com/security/cve/CVE-2021-36740 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1982409 Issue Tracking
- https://docs.varnish-software.com/security/VSV00007/ x_refsource_MISCMitigationVendor Advisory
- https://github.com/varnishcache/varnish-cache/commit/82b0a629f60136e76112c6f2c6372cce77b683be x_refsource_MISCPatchThird Party Advisory
- https://github.com/varnishcache/varnish-cache/commit/9be22198e258d0e7a5c41f4291792214a29405cf x_refsource_MISCPatchThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/THV2DQA2GS65HUCKK4KSD2XLN3AAQ2V5/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZHBNLDEOTGYRIEQZBWV7F6VPYS4O2AAK/ vendor-advisoryx_refsource_FEDORA
- https://nvd.nist.gov/vuln/detail/CVE-2021-36740
- https://varnish-cache.org/security/VSV00007.html x_refsource_MISCMitigationVendor Advisory
- https://www.cve.org/CVERecord?id=CVE-2021-36740
- https://www.debian.org/security/2022/dsa-5088 vendor-advisoryx_refsource_DEBIANThird Party Advisory
Change history (0)
No recorded changes yet.