Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update Varnish 6.0 (LTS) and 6.2 versions #47

Closed
wants to merge 1 commit into from
Closed

Update Varnish 6.0 (LTS) and 6.2 versions #47

wants to merge 1 commit into from

Conversation

samford
Copy link

@samford samford commented Sep 19, 2019

This updates to the 6.0.4 and 6.2.1 versions of Varnish, which address the VSV00003 DoS attack vector (CVE-2019-15892).

More info here: https://varnish-cache.org/security/VSV00003.html

@pborreli
Copy link

lgtm

@samford
Copy link
Author

samford commented Oct 22, 2019

I've updated this PR to the 6.0.5 and 6.2.2 versions of Varnish, which address the VSV00004 workspace information leak. More info here: https://varnish-cache.org/security/VSV00004.html

I've switched to the official Docker image for Varnish but I feel like there's still some value in merging this to update the versions, so long as this remains available on Docker Hub.

@samford samford closed this Oct 22, 2019
@samford samford deleted the update-versions branch October 22, 2019 16:33
@samford samford restored the update-versions branch October 22, 2019 16:38
@samford
Copy link
Author

samford commented Oct 22, 2019

In the process of updating the official Varnish Docker images (a different repo with the same name) and doing some cleanup after the merge, I accidentally deleted my remote branch for this repo which contained these updates. I've restored the branch, so I'm reopening this.

@samford samford reopened this Oct 22, 2019
@samford
Copy link
Author

samford commented Feb 5, 2020

I updated this PR to use versions 6.0.6 (LTS) and 6.2.3 to address VSV00005. I imagine this repo isn't being maintained anymore but I figured I may as well update this anyway.

@soyuka
Copy link

soyuka commented Feb 18, 2020

ping @teohhanhui ?

@tpo tpo mentioned this pull request May 3, 2020
@samford
Copy link
Author

samford commented Nov 8, 2020

Version 6.0.7 (LTS) has been released and the download URL now contains a unique string, so this repository's update.sh file doesn't generate the correct URLs anymore. update.sh creates https://varnish-cache.org/_downloads/varnish-6.0.7.tgz (404), whereas the URL from the first-party website that works is https://varnish-cache.org/_downloads/41841608341add28256b374dc367af04/varnish-6.0.7.tgz.

Seeing as this repository hasn't been updated to include the 6.3.x, 6.4.x, or 6.5.x releases and this PR for important security fixes to the 6.0.x and 6.2 series has been open and unmerged for over a year, I'm going to go ahead and close this. Bringing this repository up to date would require more work than what's in this PR and users are better off simply using the official varnish images at this point.

@samford samford closed this Nov 8, 2020
@samford samford deleted the update-versions branch November 8, 2020 03:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants