CVE-2019-20637
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD
Description
An issue was discovered in Varnish Cache before 6.0.5 LTS, 6.1.x and 6.2.x before 6.2.2, and 6.3.x before 6.3.1. It does not clear a pointer between the handling of one client request and the next request within the same connection. This sometimes causes information to be disclosed from the connection workspace, such as data structures associated with previous requests within this connection or VCL-related temporary headers.
Affected (5)
Products: Varnish Cache: Varnish Cache · Varnish Software: Varnish Cache · Opensuse: Backports Sle, Leap
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 6.1.0 to 6.2.2 | |
| From 6.0.0 to 6.0.5 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 15.0 sp1 | |
| Version 15.1 |
References (6)
Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.