CVE-2021-28543 - CVE House
Back to Database
Status published Medium CVE-2021-28543

Varnish varnish-modules before 0.17.1 allows remote attackers to cause a...

Vulnerability Description

Varnish varnish-modules before 0.17.1 allows remote attackers to cause a denial of service (daemon restart) in some configurations. This does not affect organizations that only install the Varnish Cache product; however, it is common to install both Varnish Cache and varnish-modules. Specifically, an assertion failure or NULL pointer dereference can be triggered in Varnish Cache through the varnish-modules header.append() and header.copy() functions. For some Varnish Configuration Language (VCL) files, this gives remote clients an opportunity to cause a Varnish Cache restart. A restart reduces overall availability and performance due to an increased number of cache misses, and may cause higher load on backend servers.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-28543

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

varnish-cache

View all reports →

Affected Software

varnish-modules, varnish-modules klarlack, fedora
Vulnerable Versions:
0, 34

Timeline

Official Publish: March 16th, 2021
Last Modified: August 3rd, 2024
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AC:H/AV:N/A:L/C:N/I:N/PR:N/S:C/UI:N

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.