CVE-2019-20637
Summary
| CVE | CVE-2019-20637 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-04-08 23:15:00 UTC |
| Updated | 2022-08-02 19:03:00 UTC |
| Description | An issue was discovered in Varnish Cache before 6.0.5 LTS, 6.1.x and 6.2.x before 6.2.2, and 6.3.x before 6.3.1. It does not clear a pointer between the handling of one client request and the next request within the same connection. This sometimes causes information to be disclosed from the connection workspace, such as data structures associated with previous requests within this connection or VCL-related temporary headers. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [security-announce] openSUSE-SU-2020:0819-1: moderate: Security update f |
SUSE |
lists.opensuse.org |
|
| [security-announce] openSUSE-SU-2020:0808-1: moderate: Security update f |
SUSE |
lists.opensuse.org |
|
| VSV00004 Workspace information leak — Varnish HTTP Cache |
MISC |
varnish-cache.org |
Vendor Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 198827 Ubuntu Security Notification for Varnish Cache Vulnerabilities (USN-5474-1)
- 376890 Alibaba Cloud Linux Security Update for varnish:6 (ALINUX3-SA-2022:0024)
- 940035 AlmaLinux Security Update for varnish:6 (ALSA-2020:4756)
- 960778 Rocky Linux Security Update for varnish:6 (RLSA-2020:4756)