CVE-2019-20637
published 2020-04-08CVE-2019-20637: An issue was discovered in Varnish Cache before 6.0.5 LTS, 6.1.x and 6.2.x before 6.2.2, and 6.3.x before 6.3.1. It does not clear a pointer between the…
PriorityP341high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
1.75%
75.3th percentile
An issue was discovered in Varnish Cache before 6.0.5 LTS, 6.1.x and 6.2.x before 6.2.2, and 6.3.x before 6.3.1. It does not clear a pointer between the handling of one client request and the next request within the same connection. This sometimes causes information to be disclosed from the connection workspace, such as data structures associated with previous requests within this connection or VCL-related temporary headers.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | varnish | < varnish 6.4.0-1 (bookworm) | varnish 6.4.0-1 (bookworm) |
| opensuse | backports_sle | — | — |
| opensuse | leap | — | — |
| varnish-cache | varnish | >= 0 < 6.4.0-1 | 6.4.0-1 |
| varnish-cache | varnish | >= 0 < 6.4.0-1 | 6.4.0-1 |
| varnish-cache | varnish | >= 0 < 6.4.0-1 | 6.4.0-1 |
| varnish-cache | varnish | >= 0 < 6.4.0-1 | 6.4.0-1 |
| varnish-cache | varnish | >= 0 < 5.2.1-1ubuntu0.1 | 5.2.1-1ubuntu0.1 |
| varnish-cache | varnish | >= 0 < 6.2.1-2ubuntu0.1 | 6.2.1-2ubuntu0.1 |
| varnish-cache | varnish | >= 0 < 6.6.1-1ubuntu0.2 | 6.6.1-1ubuntu0.2 |
| varnish-cache | varnish_cache | >= 6.1.0 < 6.2.2 | 6.2.2 |
| varnish-cache | varnish_cache | >= 6.3.0 < 6.3.1 | 6.3.1 |
| varnish-software | varnish_cache | >= 6.0.0 < 6.0.5 | 6.0.5 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Varnish Cache vulnerabilities
vendor_ubuntu·2022-06-08·CVSS 7.5
CVE-2021-36740 [HIGH] Varnish Cache vulnerabilities
Title: Varnish Cache vulnerabilities
Summary: Several security issues were fixed in Varnish Cache.
It was dicovered that Varnish Cache did not clear a pointer between the
handling of one client request and the next request within the same connection.
A remote attacker could possibly use this issue to obtain sensitive
information. (CVE-2019-20637)
It was discovered that Varnish Cache could have an assertion failure when a
TLS termination proxy uses PROXY version 2. A remote attacker could possibly
use this issue to restart the daemon and cause a performance loss.
(CVE-2020-11653)
It was discovered that Varnish Cache allowed request smuggling and VCL
authorization bypass via a large Content-Length header for a POST
request. A remote attacker could possibly use this issue to obtain sensit
Red Hat
varnish: not clearing pointer between two client requests leads to information disclosure
vendor_redhat·2019-10-21·CVSS 7.5
CVE-2019-20637 [HIGH] CWE-200 varnish: not clearing pointer between two client requests leads to information disclosure
varnish: not clearing pointer between two client requests leads to information disclosure
An issue was discovered in Varnish Cache before 6.0.5 LTS, 6.1.x and 6.2.x before 6.2.2, and 6.3.x before 6.3.1. It does not clear a pointer between the handling of one client request and the next request within the same connection. This sometimes causes information to be disclosed from the connection workspace, such as data structures associated with previous requests within this connection or VCL-related temporary headers.
Package: rh-varnish5-varnish (Red Hat Software Collections) - Fix deferred
Package: rh-varnish6-varnish (Red Hat Software Collections) - Affected
Debian
CVE-2019-20637: varnish - An issue was discovered in Varnish Cache before 6.0.5 LTS, 6.1.x and 6.2.x befor...
vendor_debian·2019·CVSS 7.5
CVE-2019-20637 [HIGH] CVE-2019-20637: varnish - An issue was discovered in Varnish Cache before 6.0.5 LTS, 6.1.x and 6.2.x befor...
An issue was discovered in Varnish Cache before 6.0.5 LTS, 6.1.x and 6.2.x before 6.2.2, and 6.3.x before 6.3.1. It does not clear a pointer between the handling of one client request and the next request within the same connection. This sometimes causes information to be disclosed from the connection workspace, such as data structures associated with previous requests within this connection or VCL-related temporary headers.
Scope: local
bookworm: resolved (fixed in 6.4.0-1)
bullseye: resolved (fixed in 6.4.0-1)
forky: resolved (fixed in 6.4.0-1)
sid: resolved (fixed in 6.4.0-1)
trixie: resolved (fixed in 6.4.0-1)
OSV
varnish vulnerabilities
osv·2022-06-08·CVSS 7.5
CVE-2019-20637 [HIGH] varnish vulnerabilities
varnish vulnerabilities
It was dicovered that Varnish Cache did not clear a pointer between the
handling of one client request and the next request within the same connection.
A remote attacker could possibly use this issue to obtain sensitive
information. (CVE-2019-20637)
It was discovered that Varnish Cache could have an assertion failure when a
TLS termination proxy uses PROXY version 2. A remote attacker could possibly
use this issue to restart the daemon and cause a performance loss.
(CVE-2020-11653)
It was discovered that Varnish Cache allowed request smuggling and VCL
authorization bypass via a large Content-Length header for a POST
request. A remote attacker could possibly use this issue to obtain sensitive
information. (CVE-2021-36740)
It was discovered that Varnish Cache allo
GHSA
GHSA-h2vv-cmjp-m2w5: An issue was discovered in Varnish Cache before 6
ghsa_unreviewed·2022-05-24
CVE-2019-20637 [MEDIUM] CWE-200 GHSA-h2vv-cmjp-m2w5: An issue was discovered in Varnish Cache before 6
An issue was discovered in Varnish Cache before 6.0.5 LTS, 6.1.x and 6.2.x before 6.2.2, and 6.3.x before 6.3.1. It does not clear a pointer between the handling of one client request and the next request within the same connection. This sometimes causes information to be disclosed from the connection workspace, such as data structures associated with previous requests within this connection or VCL-related temporary headers.
OSV
CVE-2019-20637: An issue was discovered in Varnish Cache before 6
osv·2020-04-08·CVSS 7.5
CVE-2019-20637 [HIGH] CVE-2019-20637: An issue was discovered in Varnish Cache before 6
An issue was discovered in Varnish Cache before 6.0.5 LTS, 6.1.x and 6.2.x before 6.2.2, and 6.3.x before 6.3.1. It does not clear a pointer between the handling of one client request and the next request within the same connection. This sometimes causes information to be disclosed from the connection workspace, such as data structures associated with previous requests within this connection or VCL-related temporary headers.
No detection rules found.
No public exploits indexed.
Bugzilla
varnish: uncleared pointer between handling two clients on same network could result in information leak? [epel-all]
bugzilla·2020-03-16
[MEDIUM] varnish: uncleared pointer between handling two clients on same network could result in information leak? [epel-all]
varnish: uncleared pointer between handling two clients on same network could result in information leak? [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issu
Bugzilla
CVE-2019-20637 varnish: not clearing pointer between two client requests leads to information disclosure
bugzilla·2019-11-14·CVSS 7.5
CVE-2019-20637 [HIGH] CVE-2019-20637 varnish: not clearing pointer between two client requests leads to information disclosure
CVE-2019-20637 varnish: not clearing pointer between two client requests leads to information disclosure
A bug has been discovered in Varnish Cache where we fail to clear a pointer between the handling of one client requests and the next on the same connection. This can under specific circumstances lead to information being leaked from the connection workspace.
Upstream Reference:
http://varnish-cache.org/security/VSV00004.html#vsv00004
Discussion:
Created varnish tracking bugs for this issue:
Affects: fedora-all [bug 1772363]
---
Upstream commit for this issue:
https://github.com/varnishcache/varnish-cache/commit/bd7b3d6d47ccbb5e1747126f8e2a297f38e56b8c
---
VSV00004 was fixed in rawhide 2019-10-22.
f29
Submitted: 2019-10-22
Testing: 2010-10-25
Stable: 2019-11-02
f30
Submitted
http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00026.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-06/msg00031.htmlhttp://varnish-cache.org/security/VSV00004.html#vsv00004http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00026.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-06/msg00031.htmlhttp://varnish-cache.org/security/VSV00004.html#vsv00004
2020-04-08
Published