An issue was discovered in Varnish Cache before 6.0.5 LTS, 6.1.x and 6.2.x before 6.2.2, and 6.3.x before 6.3.1. It does not clear a pointer between the handling of one client request and the next request within the same connection. This sometimes causes information to be disclosed from the connection workspace, such as data structures associated with previous requests within this connection or VCL-related temporary headers.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade varnish-develUpgrade varnish-modulesUpgrade varnish-docsUpgrade varnish | May 4, 2022 | Apr 8, 2020 |
| Centos_linux | — | Upgrade varnishUpgrade varnish-modulesUpgrade varnish-modules-debugsourceUpgrade varnish-docsUpgrade varnish-develUpgrade varnish-modules-debuginfo | Nov 5, 2020 | Apr 8, 2020 |
| Debian | — | Upgrade varnish | Jul 30, 2024 | Apr 8, 2020 |
| Oracle_linux | — | Upgrade varnishUpgrade varnish-modulesUpgrade varnish-docsUpgrade varnish-devel | Nov 12, 2020 | Oct 21, 2019 |
| Redhat_linux | — | Upgrade varnish-docsUpgrade varnishUpgrade varnish-modulesUpgrade varnish-modules-debugsourceUpgrade varnish-modules-debuginfoUpgrade varnish-devel | Nov 5, 2020 | Apr 8, 2020 |
| Rocky_linux | — | Upgrade varnish-modules-debugsourceUpgrade varnish-modules-debuginfoUpgrade varnishUpgrade varnish-develUpgrade varnish-modulesUpgrade varnish-docs | Mar 12, 2024 | Apr 8, 2020 |
| Suse | — | Upgrade varnishUpgrade libvarnishapi2Upgrade varnish-devel | Jun 16, 2020 | Apr 8, 2020 |
| Ubuntu | — | Upgrade varnishUpgrade libvarnishapi1Upgrade libvarnishapi2 | Jun 9, 2022 | Apr 8, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub