Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2019-20637

Опубликовано: 08 апр. 2020
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 5
CVSS3: 7.5

Описание

An issue was discovered in Varnish Cache before 6.0.5 LTS, 6.1.x and 6.2.x before 6.2.2, and 6.3.x before 6.3.1. It does not clear a pointer between the handling of one client request and the next request within the same connection. This sometimes causes information to be disclosed from the connection workspace, such as data structures associated with previous requests within this connection or VCL-related temporary headers.

РелизСтатусПримечание
bionic

released

5.2.1-1ubuntu0.1
devel

not-affected

6.4.0-2
eoan

ignored

end of life
esm-apps-legacy/xenial

not-affected

code not present
esm-apps/bionic

released

5.2.1-1ubuntu0.1
esm-apps/focal

released

6.2.1-2ubuntu0.1
esm-apps/jammy

not-affected

6.4.0-2
esm-apps/xenial

not-affected

code not present
esm-infra-legacy/trusty

not-affected

code not present
focal

released

6.2.1-2ubuntu0.1

Показывать по

EPSS

Процентиль: 76%
0.01746
Низкий

5 Medium

CVSS2

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 3.1
redhat
почти 7 лет назад

An issue was discovered in Varnish Cache before 6.0.5 LTS, 6.1.x and 6.2.x before 6.2.2, and 6.3.x before 6.3.1. It does not clear a pointer between the handling of one client request and the next request within the same connection. This sometimes causes information to be disclosed from the connection workspace, such as data structures associated with previous requests within this connection or VCL-related temporary headers.

CVSS3: 7.5
nvd
больше 6 лет назад

An issue was discovered in Varnish Cache before 6.0.5 LTS, 6.1.x and 6.2.x before 6.2.2, and 6.3.x before 6.3.1. It does not clear a pointer between the handling of one client request and the next request within the same connection. This sometimes causes information to be disclosed from the connection workspace, such as data structures associated with previous requests within this connection or VCL-related temporary headers.

CVSS3: 7.5
debian
больше 6 лет назад

An issue was discovered in Varnish Cache before 6.0.5 LTS, 6.1.x and 6 ...

CVSS3: 7.5
github
около 4 лет назад

An issue was discovered in Varnish Cache before 6.0.5 LTS, 6.1.x and 6.2.x before 6.2.2, and 6.3.x before 6.3.1. It does not clear a pointer between the handling of one client request and the next request within the same connection. This sometimes causes information to be disclosed from the connection workspace, such as data structures associated with previous requests within this connection or VCL-related temporary headers.

suse-cvrf
около 6 лет назад

Security update for varnish

EPSS

Процентиль: 76%
0.01746
Низкий

5 Medium

CVSS2

7.5 High

CVSS3

Уязвимость CVE-2019-20637