{"id":"CVE-2023-41104","details":"libvmod-digest before 1.0.3, as used in Varnish Enterprise 6.0.x before 6.0.11r5, has an out-of-bounds memory access during base64 decoding, leading to both authentication bypass and information disclosure; however, the exact attack surface will depend on the particular VCL (Varnish Configuration Language) configuration in use.","modified":"2026-04-11T12:45:25.188537Z","published":"2023-08-23T07:15:08.417Z","database_specific":{"unresolved_ranges":[{"cpe":"cpe:2.3:a:varnish-software:varnish_enterprise:*:*:*:*:*:*:*:*","source":"CPE_FIELD","extracted_events":[{"introduced":"6.0.0"},{"fixed":"6.0.11"}]},{"cpe":"cpe:2.3:a:varnish-software:varnish_enterprise:6.0.11:-:*:*:*:*:*:*","source":"CPE_FIELD","extracted_events":[{"last_affected":"6.0.11-NA"}]},{"cpe":"cpe:2.3:a:varnish-software:varnish_enterprise:6.0.11:r1:*:*:*:*:*:*","source":"CPE_FIELD","extracted_events":[{"last_affected":"6.0.11-r1"}]},{"cpe":"cpe:2.3:a:varnish-software:varnish_enterprise:6.0.11:r2:*:*:*:*:*:*","source":"CPE_FIELD","extracted_events":[{"last_affected":"6.0.11-r2"}]},{"cpe":"cpe:2.3:a:varnish-software:varnish_enterprise:6.0.11:r3:*:*:*:*:*:*","source":"CPE_FIELD","extracted_events":[{"last_affected":"6.0.11-r3"}]},{"cpe":"cpe:2.3:a:varnish-software:varnish_enterprise:6.0.11:r4:*:*:*:*:*:*","source":"CPE_FIELD","extracted_events":[{"last_affected":"6.0.11-r4"}]}]},"references":[{"type":"ADVISORY","url":"https://docs.varnish-software.com/security/VSV00012/"},{"type":"ADVISORY","url":"https://github.com/varnish/libvmod-digest/releases/tag/libvmod-digest-1.0.3"},{"type":"FIX","url":"https://www.varnish-cache.org/security/VSV00012.html"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/varnish/libvmod-digest","events":[{"introduced":"0"},{"fixed":"e745761469b55e83e1fca21dd0cb8eca8022935d"}],"database_specific":{"cpe":"cpe:2.3:a:varnish-software:vmod_digest:*:*:*:*:*:*:*:*","source":["CPE_FIELD","REFERENCES"],"extracted_events":[{"introduced":"0"},{"fixed":"1.0.3"}]}}],"versions":["0.1","0.2","0.3","6.4","6.6","libvmod-digest-1.0.0","libvmod-digest-1.0.1","libvmod-digest-1.0.2"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-41104.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"}]}