CVE-2019-20637
varnish: not clearing pointer between two client requests leads to information disclosure
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
An issue was discovered in Varnish Cache before 6.0.5 LTS, 6.1.x and 6.2.x before 6.2.2, and 6.3.x before 6.3.1. It does not clear a pointer between the handling of one client request and the next request within the same connection. This sometimes causes information to be disclosed from the connection workspace, such as data structures associated with previous requests within this connection or VCL-related temporary headers.
Se detectó un problema en Varnish Cache versiones anteriores a 6.0.5 LTS, versiones 6.1.x y versiones 6.2.x anteriores a 6.2.2 y versiones 6.3.x anteriores a 6.3.1. No borra un puntero entre el manejo de una petición de cliente y la siguiente petición dentro de la misma conexión. Esto a veces causa que la información sea revelada desde el espacio de trabajo de la conexión, tales como las estructuras de datos asociadas con peticiones anteriores dentro de esta conexión o los encabezados temporales relacionados con VCL.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-04-08 CVE Reserved
- 2020-04-08 CVE Published
- 2024-02-11 EPSS Updated
- 2024-08-05 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
- CWE-212: Improper Removal of Sensitive Information Before Storage or Transfer
CAPEC
References (5)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Varnish-cache Search vendor "Varnish-cache" | Varnish Cache Search vendor "Varnish-cache" for product "Varnish Cache" | >= 6.1.0 < 6.2.2 Search vendor "Varnish-cache" for product "Varnish Cache" and version " >= 6.1.0 < 6.2.2" | - |
Affected
| ||||||
Varnish-cache Search vendor "Varnish-cache" | Varnish Cache Search vendor "Varnish-cache" for product "Varnish Cache" | >= 6.3.0 < 6.3.1 Search vendor "Varnish-cache" for product "Varnish Cache" and version " >= 6.3.0 < 6.3.1" | - |
Affected
| ||||||
Varnish-software Search vendor "Varnish-software" | Varnish Cache Search vendor "Varnish-software" for product "Varnish Cache" | >= 6.0.0 < 6.0.5 Search vendor "Varnish-software" for product "Varnish Cache" and version " >= 6.0.0 < 6.0.5" | lts |
Affected
| ||||||
Opensuse Search vendor "Opensuse" | Backports Sle Search vendor "Opensuse" for product "Backports Sle" | 15.0 Search vendor "Opensuse" for product "Backports Sle" and version "15.0" | sp1 |
Affected
| ||||||
Opensuse Search vendor "Opensuse" | Leap Search vendor "Opensuse" for product "Leap" | 15.1 Search vendor "Opensuse" for product "Leap" and version "15.1" | - |
Affected
|