Lucene search

K
redhatcveRedhat.comRH:CVE-2019-15892
HistorySep 26, 2019 - 5:51 p.m.

CVE-2019-15892

2019-09-2617:51:01
redhat.com
access.redhat.com
10

EPSS

0.042

Percentile

92.4%

A flaw was found in the way Varnish parsed certain HTTP/1 requests. A remote attacker could use this flaw to crash Varnish by sending specially crafted multiple HTTP/1 requests processed on the same HTTP/1 keep-alive connection. This causes Varnish to restart with a clean cache, causing a denial of service.

Mitigation

This flaw can be mitigated by using making changes in varnish configuration by using VCL (Varnish Configuration Language). More details available at: <https://varnish-cache.org/security/VSV00003-mitigation.html#vsv00003-mitigation&gt;