Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Thu, 3 Jul 2014 22:27:15 +0200
From: Stefan B├╝hler <>
Subject: Re: Varnish - no CVE == bug regression


On Thu, 3 Jul 2014 21:07:39 +0100
Marek Kroemeke <> wrote:

> I doubt that CDNs like Akamai, Fastly(varnish?), Cloudflare(nginx?)
> etc.. would agree that the fact that a core part of their
> infrastructure could be DoSed by one of their users is not a security
> vulnerability, but I'm happy to be in minority regarding this view.

As long as varnish has no high priority to protect itself against
malicious backends I'd say it is not suited to be a frontend proxy in a
CDN network (you could use a seperate varnish instance for each
application/"trust group" though).

Different implementations have different priorities; choose one that
matches your requirements.


Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.