Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-92x2-jw7w-xvvx

Опубликовано: 07 фев. 2022
Источник: github
Github: Прошло ревью
CVSS4: 8.7
CVSS3: 7.5

Описание

Cookie and header exposure in twisted

Impact

Cookie and Authorization headers are leaked when following cross-origin redirects in twited.web.client.RedirectAgent and twisted.web.client.BrowserLikeRedirectAgent.

Пакеты

Наименование

Twisted

pip
Затронутые версииВерсия исправления

>= 11.1.0, < 22.1.0

22.1.0

EPSS

Процентиль: 47%
0.00241
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-200
CWE-346

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 4 года назад

twisted is an event-driven networking engine written in Python. In affected versions twisted exposes cookies and authorization headers when following cross-origin redirects. This issue is present in the `twited.web.RedirectAgent` and `twisted.web. BrowserLikeRedirectAgent` functions. Users are advised to upgrade. There are no known workarounds.

CVSS3: 7.5
redhat
почти 4 года назад

twisted is an event-driven networking engine written in Python. In affected versions twisted exposes cookies and authorization headers when following cross-origin redirects. This issue is present in the `twited.web.RedirectAgent` and `twisted.web. BrowserLikeRedirectAgent` functions. Users are advised to upgrade. There are no known workarounds.

CVSS3: 7.5
nvd
почти 4 года назад

twisted is an event-driven networking engine written in Python. In affected versions twisted exposes cookies and authorization headers when following cross-origin redirects. This issue is present in the `twited.web.RedirectAgent` and `twisted.web. BrowserLikeRedirectAgent` functions. Users are advised to upgrade. There are no known workarounds.

CVSS3: 7.5
msrc
почти 4 года назад

Cookie and header exposure in twisted

CVSS3: 7.5
debian
почти 4 года назад

twisted is an event-driven networking engine written in Python. In aff ...

EPSS

Процентиль: 47%
0.00241
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-200
CWE-346