ibexa/http-cache
HTTP cache handling for Ibexa DXP.
Activity
- Latest release
- 3w ago
- Total releases
- 112
- Cadence
- ~18 days
- Last 12 months
- 16
Reach
- Stars
- 4
Details
- License
- GPL-2.0-only OR custom
- First release
- Nov 22, 2021
| Version | Released | |
|---|---|---|
v5.0.10
patch
|
v5.0.10
patch
Dependencies (14)
+ 6 more
Changelog
Compare changes
|
|
v4.6.32
patch
|
v4.6.32
patch
Dependencies (14)
+ 6 more
Changelog
Compare changes
|
|
v5.0.9
patch
|
v5.0.9
patch
Dependencies (14)
+ 6 more
Changelog
Compare changes
|
|
v4.6.31
patch
|
v4.6.31
patch
Dependencies (14)
+ 6 more
Changelog
Compare changes
|
|
v5.0.8
patch
| ||
v4.6.30
patch
| ||
v5.0.7
patch
| ||
v4.6.29
patch
| ||
v5.0.6
patch
|
v5.0.6
patch
Dependencies (14)
+ 6 more
Changelog
Compare changes
|
|
v4.6.28
patch
| ||
v4.6.27
patch
| ||
v5.0.5
patch
| ||
v5.0.4
patch
| ||
v4.6.26
patch
| ||
v5.0.3
patch
| ||
v4.6.25
patch
| ||
v5.0.2
patch
| ||
v4.6.24
patch
| ||
v5.0.1
patch
| ||
v4.6.23
patch
| ||
v4.6.22
patch
| ||
v5.0.0
major
| ||
v5.0.0-rc1
pre
|
v5.0.0-rc1
pre
Dependencies (14)
+ 6 more
Changelog
Compare changes
|
|
v5.0.0-beta1
pre
|
v5.0.0-beta1
pre
Dependencies (14)
+ 6 more
Changelog
Compare changes
|
|
v4.6.21
patch
| ||
v4.6.20
patch
| ||
v4.6.19
patch
| ||
v4.6.18
patch
| ||
v4.6.17
patch
| ||
v4.6.16
patch
| ||
v4.6.15
patch
| ||
v4.6.14
patch
| ||
v4.6.13
patch
1 CVE
GHSA-fh7v-q458-7vmw
Dec 02, 2024
ibexa/http-cache affected by Breach with Varnish VCL
Medium
ImpactThis is not a vulnerability in the code per se, but included Varnish VCL templates enable compression of API and JSON messages. This is a potential case of the BREACH vulnerability, which affects HTTP compression, where secrets can be extracted through carefully crafted requests. The fix disables compression in these templates. Please make sure to make the same change in your configuration files, see the release notes for specific instructions. Please check your web server configuration as well. Patches
WorkaroundsMake sure HTTP compression is disabled for REST API requests and other communication that might contain secrets. References
Affected versions
v4.6.0
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
+ 2 more Show less
v4.6.8
v4.6.9
Fixed in
4.6.14
References
Updated Dec 02, 2024 · Source: OSV.dev | ||
v4.6.12
patch
1 CVE
GHSA-fh7v-q458-7vmw
Dec 02, 2024
ibexa/http-cache affected by Breach with Varnish VCL
Medium
ImpactThis is not a vulnerability in the code per se, but included Varnish VCL templates enable compression of API and JSON messages. This is a potential case of the BREACH vulnerability, which affects HTTP compression, where secrets can be extracted through carefully crafted requests. The fix disables compression in these templates. Please make sure to make the same change in your configuration files, see the release notes for specific instructions. Please check your web server configuration as well. Patches
WorkaroundsMake sure HTTP compression is disabled for REST API requests and other communication that might contain secrets. References
Affected versions
v4.6.0
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
+ 2 more Show less
v4.6.8
v4.6.9
Fixed in
4.6.14
References
Updated Dec 02, 2024 · Source: OSV.dev | ||
v4.6.11
patch
1 CVE
GHSA-fh7v-q458-7vmw
Dec 02, 2024
ibexa/http-cache affected by Breach with Varnish VCL
Medium
ImpactThis is not a vulnerability in the code per se, but included Varnish VCL templates enable compression of API and JSON messages. This is a potential case of the BREACH vulnerability, which affects HTTP compression, where secrets can be extracted through carefully crafted requests. The fix disables compression in these templates. Please make sure to make the same change in your configuration files, see the release notes for specific instructions. Please check your web server configuration as well. Patches
WorkaroundsMake sure HTTP compression is disabled for REST API requests and other communication that might contain secrets. References
Affected versions
v4.6.0
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
+ 2 more Show less
v4.6.8
v4.6.9
Fixed in
4.6.14
References
Updated Dec 02, 2024 · Source: OSV.dev | ||
v4.6.10
patch
1 CVE
GHSA-fh7v-q458-7vmw
Dec 02, 2024
ibexa/http-cache affected by Breach with Varnish VCL
Medium
ImpactThis is not a vulnerability in the code per se, but included Varnish VCL templates enable compression of API and JSON messages. This is a potential case of the BREACH vulnerability, which affects HTTP compression, where secrets can be extracted through carefully crafted requests. The fix disables compression in these templates. Please make sure to make the same change in your configuration files, see the release notes for specific instructions. Please check your web server configuration as well. Patches
WorkaroundsMake sure HTTP compression is disabled for REST API requests and other communication that might contain secrets. References
Affected versions
v4.6.0
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
+ 2 more Show less
v4.6.8
v4.6.9
Fixed in
4.6.14
References
Updated Dec 02, 2024 · Source: OSV.dev | ||
v4.6.9
patch
1 CVE
GHSA-fh7v-q458-7vmw
Dec 02, 2024
ibexa/http-cache affected by Breach with Varnish VCL
Medium
ImpactThis is not a vulnerability in the code per se, but included Varnish VCL templates enable compression of API and JSON messages. This is a potential case of the BREACH vulnerability, which affects HTTP compression, where secrets can be extracted through carefully crafted requests. The fix disables compression in these templates. Please make sure to make the same change in your configuration files, see the release notes for specific instructions. Please check your web server configuration as well. Patches
WorkaroundsMake sure HTTP compression is disabled for REST API requests and other communication that might contain secrets. References
Affected versions
v4.6.0
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
+ 2 more Show less
v4.6.8
v4.6.9
Fixed in
4.6.14
References
Updated Dec 02, 2024 · Source: OSV.dev | ||
v4.6.8
patch
1 CVE
GHSA-fh7v-q458-7vmw
Dec 02, 2024
ibexa/http-cache affected by Breach with Varnish VCL
Medium
ImpactThis is not a vulnerability in the code per se, but included Varnish VCL templates enable compression of API and JSON messages. This is a potential case of the BREACH vulnerability, which affects HTTP compression, where secrets can be extracted through carefully crafted requests. The fix disables compression in these templates. Please make sure to make the same change in your configuration files, see the release notes for specific instructions. Please check your web server configuration as well. Patches
WorkaroundsMake sure HTTP compression is disabled for REST API requests and other communication that might contain secrets. References
Affected versions
v4.6.0
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
+ 2 more Show less
v4.6.8
v4.6.9
Fixed in
4.6.14
References
Updated Dec 02, 2024 · Source: OSV.dev | ||
v4.6.7
patch
1 CVE
GHSA-fh7v-q458-7vmw
Dec 02, 2024
ibexa/http-cache affected by Breach with Varnish VCL
Medium
ImpactThis is not a vulnerability in the code per se, but included Varnish VCL templates enable compression of API and JSON messages. This is a potential case of the BREACH vulnerability, which affects HTTP compression, where secrets can be extracted through carefully crafted requests. The fix disables compression in these templates. Please make sure to make the same change in your configuration files, see the release notes for specific instructions. Please check your web server configuration as well. Patches
WorkaroundsMake sure HTTP compression is disabled for REST API requests and other communication that might contain secrets. References
Affected versions
v4.6.0
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
+ 2 more Show less
v4.6.8
v4.6.9
Fixed in
4.6.14
References
Updated Dec 02, 2024 · Source: OSV.dev | ||
v4.6.6
patch
1 CVE
GHSA-fh7v-q458-7vmw
Dec 02, 2024
ibexa/http-cache affected by Breach with Varnish VCL
Medium
ImpactThis is not a vulnerability in the code per se, but included Varnish VCL templates enable compression of API and JSON messages. This is a potential case of the BREACH vulnerability, which affects HTTP compression, where secrets can be extracted through carefully crafted requests. The fix disables compression in these templates. Please make sure to make the same change in your configuration files, see the release notes for specific instructions. Please check your web server configuration as well. Patches
WorkaroundsMake sure HTTP compression is disabled for REST API requests and other communication that might contain secrets. References
Affected versions
v4.6.0
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
+ 2 more Show less
v4.6.8
v4.6.9
Fixed in
4.6.14
References
Updated Dec 02, 2024 · Source: OSV.dev | ||
v4.6.5
patch
1 CVE
GHSA-fh7v-q458-7vmw
Dec 02, 2024
ibexa/http-cache affected by Breach with Varnish VCL
Medium
ImpactThis is not a vulnerability in the code per se, but included Varnish VCL templates enable compression of API and JSON messages. This is a potential case of the BREACH vulnerability, which affects HTTP compression, where secrets can be extracted through carefully crafted requests. The fix disables compression in these templates. Please make sure to make the same change in your configuration files, see the release notes for specific instructions. Please check your web server configuration as well. Patches
WorkaroundsMake sure HTTP compression is disabled for REST API requests and other communication that might contain secrets. References
Affected versions
v4.6.0
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
+ 2 more Show less
v4.6.8
v4.6.9
Fixed in
4.6.14
References
Updated Dec 02, 2024 · Source: OSV.dev | ||
v4.6.4
patch
1 CVE
GHSA-fh7v-q458-7vmw
Dec 02, 2024
ibexa/http-cache affected by Breach with Varnish VCL
Medium
ImpactThis is not a vulnerability in the code per se, but included Varnish VCL templates enable compression of API and JSON messages. This is a potential case of the BREACH vulnerability, which affects HTTP compression, where secrets can be extracted through carefully crafted requests. The fix disables compression in these templates. Please make sure to make the same change in your configuration files, see the release notes for specific instructions. Please check your web server configuration as well. Patches
WorkaroundsMake sure HTTP compression is disabled for REST API requests and other communication that might contain secrets. References
Affected versions
v4.6.0
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
+ 2 more Show less
v4.6.8
v4.6.9
Fixed in
4.6.14
References
Updated Dec 02, 2024 · Source: OSV.dev | ||
v4.6.3
patch
1 CVE
GHSA-fh7v-q458-7vmw
Dec 02, 2024
ibexa/http-cache affected by Breach with Varnish VCL
Medium
ImpactThis is not a vulnerability in the code per se, but included Varnish VCL templates enable compression of API and JSON messages. This is a potential case of the BREACH vulnerability, which affects HTTP compression, where secrets can be extracted through carefully crafted requests. The fix disables compression in these templates. Please make sure to make the same change in your configuration files, see the release notes for specific instructions. Please check your web server configuration as well. Patches
WorkaroundsMake sure HTTP compression is disabled for REST API requests and other communication that might contain secrets. References
Affected versions
v4.6.0
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
+ 2 more Show less
v4.6.8
v4.6.9
Fixed in
4.6.14
References
Updated Dec 02, 2024 · Source: OSV.dev | ||
v4.5.7
patch
|
v4.5.7
patch
Dependencies (14)
+ 6 more
Changelog
Compare changes
|
|
v4.6.2
patch
1 CVE
GHSA-fh7v-q458-7vmw
Dec 02, 2024
ibexa/http-cache affected by Breach with Varnish VCL
Medium
ImpactThis is not a vulnerability in the code per se, but included Varnish VCL templates enable compression of API and JSON messages. This is a potential case of the BREACH vulnerability, which affects HTTP compression, where secrets can be extracted through carefully crafted requests. The fix disables compression in these templates. Please make sure to make the same change in your configuration files, see the release notes for specific instructions. Please check your web server configuration as well. Patches
WorkaroundsMake sure HTTP compression is disabled for REST API requests and other communication that might contain secrets. References
Affected versions
v4.6.0
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
+ 2 more Show less
v4.6.8
v4.6.9
Fixed in
4.6.14
References
Updated Dec 02, 2024 · Source: OSV.dev |
v4.6.2
patch
Dependencies (14)
+ 6 more
Changelog
Compare changes
|
|
v4.5.6
patch
| ||
v4.6.1
patch
1 CVE
GHSA-fh7v-q458-7vmw
Dec 02, 2024
ibexa/http-cache affected by Breach with Varnish VCL
Medium
ImpactThis is not a vulnerability in the code per se, but included Varnish VCL templates enable compression of API and JSON messages. This is a potential case of the BREACH vulnerability, which affects HTTP compression, where secrets can be extracted through carefully crafted requests. The fix disables compression in these templates. Please make sure to make the same change in your configuration files, see the release notes for specific instructions. Please check your web server configuration as well. Patches
WorkaroundsMake sure HTTP compression is disabled for REST API requests and other communication that might contain secrets. References
Affected versions
v4.6.0
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
+ 2 more Show less
v4.6.8
v4.6.9
Fixed in
4.6.14
References
Updated Dec 02, 2024 · Source: OSV.dev |
v4.6.1
patch
Dependencies (14)
+ 6 more
Changelog
Compare changes
|
|
v4.6.0
minor
1 CVE
GHSA-fh7v-q458-7vmw
Dec 02, 2024
ibexa/http-cache affected by Breach with Varnish VCL
Medium
ImpactThis is not a vulnerability in the code per se, but included Varnish VCL templates enable compression of API and JSON messages. This is a potential case of the BREACH vulnerability, which affects HTTP compression, where secrets can be extracted through carefully crafted requests. The fix disables compression in these templates. Please make sure to make the same change in your configuration files, see the release notes for specific instructions. Please check your web server configuration as well. Patches
WorkaroundsMake sure HTTP compression is disabled for REST API requests and other communication that might contain secrets. References
Affected versions
v4.6.0
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
+ 2 more Show less
v4.6.8
v4.6.9
Fixed in
4.6.14
References
Updated Dec 02, 2024 · Source: OSV.dev | ||
v4.5.5
patch
| ||
v4.6.0-rc1
pre
|
v4.6.0-rc1
pre
Dependencies (14)
+ 6 more
Changelog
Compare changes
|