← Back

CVE-2019-20637

nvd nist
Published: Apr 8, 2020Modified: Jun 17, 2026

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

An issue was discovered in Varnish Cache before 6.0.5 LTS, 6.1.x and 6.2.x before 6.2.2, and 6.3.x before 6.3.1. It does not clear a pointer between the handling of one client request and the next request within the same connection. This sometimes causes information to be disclosed from the connection workspace, such as data structures associated with previous requests within this connection or VCL-related temporary headers.

Affected (5)

1 product
Varnish Cache
Varnish Cache
2 products
Backports Sle
Leap
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Varnish Cache
From 6.1.0 to 6.2.2
From 6.3.0 to 6.3.1
From 6.0.0 to 6.0.5
Configuration B
2 vulnerable
Vulnerable SoftwareAffected Versions
Version 15.0 sp1
Version 15.1

References (6)

Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.