varnish: not clearing pointer between two client requests leads to information disclosure
Published Apr 8, 2020
7.5
HIGHCVSS 3.1
EPSS 1.79%
Description
An issue was discovered in Varnish Cache before 6.0.5 LTS, 6.1.x and 6.2.x before 6.2.2, and 6.3.x before 6.3.1. It does not clear a pointer between the handling of one client request and the next request within the same connection. This sometimes causes information to be disclosed from the connection workspace, such as data structures associated with previous requests within this connection or VCL-related temporary headers.
Affected products
No data.
Configuration 1
- ≥ 6.1.0 · < 6.2.2
- ≥ 6.3.0 · < 6.3.1
- ≥ 6.0.0 · < 6.0.5
Configuration 2
- 15.0
- 15.1
No data.
Red Hat Enterprise Linux 8
varnish:6-8030020200530080205.30b713e6
Fixed · RHSA-2020:4756
Red Hat Software Collections
rh-varnish5-varnish
Fix deferred
Red Hat Software Collections
rh-varnish6-varnish
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | varnish:6-8030020200530080205.30b713e6 | Fixed | RHSA-2020:4756 |
| Red Hat Software Collections | rh-varnish5-varnish | Fix deferred | n/a |
| Red Hat Software Collections | rh-varnish6-varnish | Affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (8)
- http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00026.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00031.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://varnish-cache.org/security/VSV00004.html#vsv00004 x_refsource_MISCVendor Advisory
- https://access.redhat.com/security/cve/CVE-2019-20637 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1772362 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-11176 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-20637
- https://www.cve.org/CVERecord?id=CVE-2019-20637
| Link | Providers | Tags |
|---|---|---|
| http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00026.html | vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory | |
| http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00031.html | vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory | |
| http://varnish-cache.org/security/VSV00004.html#vsv00004 | x_refsource_MISCVendor Advisory | |
| https://access.redhat.com/security/cve/CVE-2019-20637 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1772362 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-11176 | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2019-20637 | ||
| https://www.cve.org/CVERecord?id=CVE-2019-20637 |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
GitHub
No data