Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-7263 | Varnish Enterprise before 6.0.13r13 allows remote attackers to obtain sensitive information via an out-of-bounds read for range requests on ephemeral MSE4 stevedore objects. |
| Link | Providers |
|---|---|
| https://docs.varnish-software.com/security/VEV00001/ |
|
Mon, 24 Mar 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Varnish-software
Varnish-software varnish Enterprise |
|
| CPEs | cpe:2.3:a:varnish-software:varnish_enterprise:6.0.13:r10:*:*:*:*:*:* cpe:2.3:a:varnish-software:varnish_enterprise:6.0.13:r11:*:*:*:*:*:* cpe:2.3:a:varnish-software:varnish_enterprise:6.0.13:r12:*:*:*:*:*:* cpe:2.3:a:varnish-software:varnish_enterprise:6.0.13:r2:*:*:*:*:*:* cpe:2.3:a:varnish-software:varnish_enterprise:6.0.13:r3:*:*:*:*:*:* cpe:2.3:a:varnish-software:varnish_enterprise:6.0.13:r4:*:*:*:*:*:* cpe:2.3:a:varnish-software:varnish_enterprise:6.0.13:r5:*:*:*:*:*:* cpe:2.3:a:varnish-software:varnish_enterprise:6.0.13:r6:*:*:*:*:*:* cpe:2.3:a:varnish-software:varnish_enterprise:6.0.13:r7:*:*:*:*:*:* cpe:2.3:a:varnish-software:varnish_enterprise:6.0.13:r8:*:*:*:*:*:* cpe:2.3:a:varnish-software:varnish_enterprise:6.0.13:r9:*:*:*:*:*:* |
|
| Vendors & Products |
Varnish-software
Varnish-software varnish Enterprise |
Fri, 21 Mar 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 21 Mar 2025 06:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Varnish Enterprise before 6.0.13r13 allows remote attackers to obtain sensitive information via an out-of-bounds read for range requests on ephemeral MSE4 stevedore objects. | |
| Weaknesses | CWE-125 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-03-21T15:52:47.427Z
Reserved: 2025-03-21T00:00:00.000Z
Link: CVE-2025-30347
Updated: 2025-03-21T15:52:40.917Z
Status : Analyzed
Published: 2025-03-21T07:15:37.527
Modified: 2025-03-24T14:19:23.963
Link: CVE-2025-30347
No data.
OpenCVE Enrichment
No data.
EUVD