7.5

CVE-2009-2936

The Command Line Interface (aka Server CLI or administration interface) in the master process in the reverse proxy server in Varnish before 2.1.0 does not require authentication for commands received through a TCP port, which allows remote attackers to (1) execute arbitrary code via a vcl.inline directive that provides a VCL configuration file containing inline C code; (2) change the ownership of the master process via param.set, stop, and start directives; (3) read the initial line of an arbitrary file via a vcl.load directive; or (4) conduct cross-site request forgery (CSRF) attacks that leverage a victim's location on a trusted network and improper input validation of directives.  NOTE: the vendor disputes this report, saying that it is "fundamentally misguided and pointless.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Varnish.Projects.Linpro ≫ Varnish Version 0.9.1
Varnish.Projects.Linpro ≫ Varnish Version 1.0.1
Varnish.Projects.Linpro ≫ Varnish Version 1.0.2
Varnish.Projects.Linpro ≫ Varnish Version 1.0.3
Varnish.Projects.Linpro ≫ Varnish Version 1.0.4
Varnish.Projects.Linpro ≫ Varnish Version 1.1.1
Varnish.Projects.Linpro ≫ Varnish Version 1.1.2
Varnish.Projects.Linpro ≫ Varnish Version 2.0 Update beta1
Varnish.Projects.Linpro ≫ Varnish Version 2.0 Update beta2
Varnish.Projects.Linpro ≫ Varnish Version 2.0 Update rc1
Varnish.Projects.Linpro ≫ Varnish Version 2.0.1
Varnish.Projects.Linpro ≫ Varnish Version 2.0.2
Varnish.Projects.Linpro ≫ Varnish Version 2.0.3
Varnish.Projects.Linpro ≫ Varnish Version 2.0.4
Varnish.Projects.Linpro ≫ Varnish Version 2.0.5
Varnish.Projects.Linpro ≫ Varnish Version 2.0.6
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 63.82% 0.991
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

http://lists.fedoraproject.org/pipermail/package-announce/2010-April/040359.html
http://www.securityfocus.com/archive/1/510360/100/0/threaded
http://www.securityfocus.com/archive/1/510368/100/0/threaded
http://www.varnish-cache.org/changeset/3865
http://www.varnish-cache.org/wiki/CLI