An issue was discovered in Varnish Cache before 6.0.5 LTS, 6.1.x and 6.2.x before 6.2.2, and 6.3.x before 6.3.1. It does not clear a pointer between the handling of one client request and the next request within the same connection. This sometimes causes information to be disclosed from the connection workspace, such as data structures associated with previous requests within this connection or VCL-related temporary headers.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2020-04-08T23:01:30
Updated: 2024-08-05T02:46:10.452Z
Reserved: 2020-04-08T00:00:00
Link: CVE-2019-20637
Vulnrichment
No data.
NVD
Status : Modified
Published: 2020-04-08T23:15:12.623
Modified: 2024-11-21T04:38:56.193
Link: CVE-2019-20637
Redhat