CVE-2019-20637: High severity varnish cache vulnerability
An issue was discovered in Varnish Cache before 6.0.5 LTS, 6.1.x and 6.2.x before 6.2.2, and 6.3.x before 6.3.1. It does not clear a pointer between the handling of one client request and the next request within the same connection. This sometimes causes information to be disclosed from the connection workspace, such as data structures associated with previous requests within this connection or VCL-related temporary headers.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
CVE-2019-20637
What is the severity of CVE-2019-20637?
The severity of CVE-2019-20637 is high with a severity value of 7.5.
Which versions of Varnish Cache are affected by CVE-2019-20637?
Varnish Cache versions 6.0.0 to 6.0.5 LTS, 6.1.0 to 6.2.2, and 6.3.0 to 6.3.1 are affected by CVE-2019-20637.
How does CVE-2019-20637 occur?
CVE-2019-20637 occurs when Varnish Cache does not clear a pointer between the handling of one client request and the next request within the same connection, leading to potential information disclosure.
Are there any patches or updates available for CVE-2019-20637?
Yes, patches and updates are available for CVE-2019-20637. Please refer to the vendor's website for more information.