Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2019-20637

Опубликовано: 08 апр. 2020
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 5
CVSS3: 7.5

Описание

An issue was discovered in Varnish Cache before 6.0.5 LTS, 6.1.x and 6.2.x before 6.2.2, and 6.3.x before 6.3.1. It does not clear a pointer between the handling of one client request and the next request within the same connection. This sometimes causes information to be disclosed from the connection workspace, such as data structures associated with previous requests within this connection or VCL-related temporary headers.

РелизСтатусПримечание
bionic

released

5.2.1-1ubuntu0.1
devel

not-affected

6.4.0-2
eoan

ignored

end of life
esm-apps/bionic

released

5.2.1-1ubuntu0.1
esm-apps/focal

released

6.2.1-2ubuntu0.1
esm-apps/jammy

not-affected

6.4.0-2
esm-apps/xenial

not-affected

code not present
esm-infra-legacy/trusty

not-affected

code not present
focal

released

6.2.1-2ubuntu0.1
groovy

not-affected

6.4.0-2

Показывать по

EPSS

Процентиль: 64%
0.00478
Низкий

5 Medium

CVSS2

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 3.1
redhat
около 6 лет назад

An issue was discovered in Varnish Cache before 6.0.5 LTS, 6.1.x and 6.2.x before 6.2.2, and 6.3.x before 6.3.1. It does not clear a pointer between the handling of one client request and the next request within the same connection. This sometimes causes information to be disclosed from the connection workspace, such as data structures associated with previous requests within this connection or VCL-related temporary headers.

CVSS3: 7.5
nvd
больше 5 лет назад

An issue was discovered in Varnish Cache before 6.0.5 LTS, 6.1.x and 6.2.x before 6.2.2, and 6.3.x before 6.3.1. It does not clear a pointer between the handling of one client request and the next request within the same connection. This sometimes causes information to be disclosed from the connection workspace, such as data structures associated with previous requests within this connection or VCL-related temporary headers.

CVSS3: 7.5
debian
больше 5 лет назад

An issue was discovered in Varnish Cache before 6.0.5 LTS, 6.1.x and 6 ...

CVSS3: 7.5
github
больше 3 лет назад

An issue was discovered in Varnish Cache before 6.0.5 LTS, 6.1.x and 6.2.x before 6.2.2, and 6.3.x before 6.3.1. It does not clear a pointer between the handling of one client request and the next request within the same connection. This sometimes causes information to be disclosed from the connection workspace, such as data structures associated with previous requests within this connection or VCL-related temporary headers.

suse-cvrf
больше 5 лет назад

Security update for varnish

EPSS

Процентиль: 64%
0.00478
Низкий

5 Medium

CVSS2

7.5 High

CVSS3