VDB

DEBIAN-CVE-2019-20637

DEBIAN-CVE-2019-20637 PUBLISHED CVSS 7.5 HIGH

An issue was discovered in Varnish Cache before 6.0.5 LTS, 6.1.x and 6.2.x before 6.2.2, and 6.3.x before 6.3.1. It does not clear a pointer between the handling of one client request and the next request within the same connection. This sometimes causes information to be disclosed from the connection workspace, such as data structures associated with previous requests within this connection or VCL-related temporary headers.

Risk Scores

CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected Products

VendorProductVersions
Debian:12varnish0, 0, 0
Debian:14varnish0, 0, 0
Debian:11varnish0, 0, 0
Debian:13varnish0, 0, 0

Timeline

  • Apr 8, 2020 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›