Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-20637

Опубликовано: 21 окт. 2019
Источник: redhat
CVSS3: 3.1
EPSS Низкий

Описание

An issue was discovered in Varnish Cache before 6.0.5 LTS, 6.1.x and 6.2.x before 6.2.2, and 6.3.x before 6.3.1. It does not clear a pointer between the handling of one client request and the next request within the same connection. This sometimes causes information to be disclosed from the connection workspace, such as data structures associated with previous requests within this connection or VCL-related temporary headers.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Software Collectionsrh-varnish5-varnishFix deferred
Red Hat Software Collectionsrh-varnish6-varnishAffected
Red Hat Enterprise Linux 8varnishFixedRHSA-2020:475604.11.2020

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-200
https://bugzilla.redhat.com/show_bug.cgi?id=1772362varnish: not clearing pointer between two client requests leads to information disclosure

EPSS

Процентиль: 75%
0.01746
Низкий

3.1 Low

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 6 лет назад

An issue was discovered in Varnish Cache before 6.0.5 LTS, 6.1.x and 6.2.x before 6.2.2, and 6.3.x before 6.3.1. It does not clear a pointer between the handling of one client request and the next request within the same connection. This sometimes causes information to be disclosed from the connection workspace, such as data structures associated with previous requests within this connection or VCL-related temporary headers.

CVSS3: 7.5
nvd
больше 6 лет назад

An issue was discovered in Varnish Cache before 6.0.5 LTS, 6.1.x and 6.2.x before 6.2.2, and 6.3.x before 6.3.1. It does not clear a pointer between the handling of one client request and the next request within the same connection. This sometimes causes information to be disclosed from the connection workspace, such as data structures associated with previous requests within this connection or VCL-related temporary headers.

CVSS3: 7.5
debian
больше 6 лет назад

An issue was discovered in Varnish Cache before 6.0.5 LTS, 6.1.x and 6 ...

CVSS3: 7.5
github
около 4 лет назад

An issue was discovered in Varnish Cache before 6.0.5 LTS, 6.1.x and 6.2.x before 6.2.2, and 6.3.x before 6.3.1. It does not clear a pointer between the handling of one client request and the next request within the same connection. This sometimes causes information to be disclosed from the connection workspace, such as data structures associated with previous requests within this connection or VCL-related temporary headers.

suse-cvrf
около 6 лет назад

Security update for varnish

EPSS

Процентиль: 75%
0.01746
Низкий

3.1 Low

CVSS3