Candidate: CVE-2019-20637 PublicDate: 2020-04-08 23:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-20637 http://varnish-cache.org/security/VSV00004.html#vsv00004 https://github.com/varnishcache/varnish-cache/commit/bd7b3d6d47ccbb5e1747126f8e2a297f38e56b8c Description: An issue was discovered in Varnish Cache before 6.0.5 LTS, 6.1.x and 6.2.x before 6.2.2, and 6.3.x before 6.3.1. It does not clear a pointer between the handling of one client request and the next request within the same connection. This sometimes causes information to be disclosed from the connection workspace, such as data structures associated with previous requests within this connection or VCL-related temporary headers. Ubuntu-Description: Notes: Mitigation: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=956305 Priority: medium Discovered-by: Assigned-to: ebarretto CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N [7.5 HIGH] Patches_varnish: upstream_varnish: needs-triage precise/esm_varnish: DNE trusty_varnish: ignored (out of standard support) trusty/esm_varnish: not-affected (code not present) xenial_varnish: ignored (end of standard support, was needs-triage) bionic_varnish: needed eoan_varnish: ignored (reached end-of-life) focal_varnish: needed groovy_varnish: not-affected (6.4.0-2) hirsute_varnish: not-affected (6.4.0-2) impish_varnish: not-affected (6.4.0-2) jammy_varnish: not-affected (6.4.0-2) devel_varnish: not-affected (6.4.0-2)