Medium severity6.5NVD Advisory· Published Aug 23, 2023· Updated Jun 17, 2026
CVE-2023-41104
CVE-2023-41104
Description
libvmod-digest before 1.0.3, as used in Varnish Enterprise 6.0.x before 6.0.11r5, has an out-of-bounds memory access during base64 decoding, leading to both authentication bypass and information disclosure; however, the exact attack surface will depend on the particular VCL (Varnish Configuration Language) configuration in use.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
10cpe:2.3:a:varnish-software:varnish_enterprise:*:*:*:*:*:*:*:*+ 6 more
- cpe:2.3:a:varnish-software:varnish_enterprise:*:*:*:*:*:*:*:*range: >=6.0.0,<6.0.11
- cpe:2.3:a:varnish-software:varnish_enterprise:6.0.11:-:*:*:*:*:*:*
- cpe:2.3:a:varnish-software:varnish_enterprise:6.0.11:r1:*:*:*:*:*:*
- cpe:2.3:a:varnish-software:varnish_enterprise:6.0.11:r2:*:*:*:*:*:*
- cpe:2.3:a:varnish-software:varnish_enterprise:6.0.11:r3:*:*:*:*:*:*
- cpe:2.3:a:varnish-software:varnish_enterprise:6.0.11:r4:*:*:*:*:*:*
- (no CPE)range: <6.0.11r5
- Varnish Enterprise/libvmod-digestdescription
- Range: <1.0.3
Patches
Vulnerability mechanics
References
3- www.varnish-cache.org/security/VSV00012.htmlnvdPatchVendor Advisory
- docs.varnish-software.com/security/VSV00012/nvdMitigationVendor Advisory
- github.com/varnish/libvmod-digest/releases/tag/libvmod-digest-1.0.3nvdRelease Notes
News mentions
0No linked articles in our index yet.