Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-12387

Опубликовано: 10 июн. 2019
Источник: debian

Описание

In Twisted before 19.2.1, twisted.web did not validate or sanitize URIs or HTTP methods, allowing an attacker to inject invalid characters such as CRLF.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
twistedfixed18.9.0-7package
twistedfixed18.9.0-3+deb10u1busterpackage
twistedno-dsastretchpackage
twistedno-dsajessiepackage

Примечания

  • https://github.com/twisted/twisted/commit/6c61fc4503ae39ab8ecee52d10f10ee2c371d7e2

Связанные уязвимости

CVSS3: 6.1
ubuntu
больше 6 лет назад

In Twisted before 19.2.1, twisted.web did not validate or sanitize URIs or HTTP methods, allowing an attacker to inject invalid characters such as CRLF.

CVSS3: 6.5
redhat
больше 6 лет назад

In Twisted before 19.2.1, twisted.web did not validate or sanitize URIs or HTTP methods, allowing an attacker to inject invalid characters such as CRLF.

CVSS3: 6.1
nvd
больше 6 лет назад

In Twisted before 19.2.1, twisted.web did not validate or sanitize URIs or HTTP methods, allowing an attacker to inject invalid characters such as CRLF.

suse-cvrf
больше 6 лет назад

Security update for python-Twisted

suse-cvrf
больше 6 лет назад

Security update for python-Twisted