Candidate: CVE-2013-4090 PublicDate: 2020-02-12 16:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4090 https://www.varnish-cache.org/lists/pipermail/varnish-announce/2013-June/000684.html Description: Varnish HTTP cache before 3.0.4: ACL bug Ubuntu-Description: Notes: Mitigation: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N [7.5 HIGH] Patches_varnish: upstream_varnish: released (3.0.4) precise/esm_varnish: DNE trusty_varnish: ignored (out of standard support) trusty/esm_varnish: not-affected (3.0.5-2ubuntu0.1) xenial_varnish: not-affected (3.0.5-2ubuntu0.1) bionic_varnish: not-affected (3.0.5-2ubuntu0.1) eoan_varnish: not-affected (3.0.5-2ubuntu0.1) devel_varnish: not-affected (3.0.5-2ubuntu0.1)