Описание
In Twisted before 19.2.1, twisted.web did not validate or sanitize URIs or HTTP methods, allowing an attacker to inject invalid characters such as CRLF.
Ссылки
- Broken Link
- Broken Link
- PatchThird Party Advisory
- ExploitRelease NotesVendor Advisory
- ExploitRelease NotesVendor Advisory
- Third Party Advisory
- Third Party Advisory
- PatchThird Party Advisory
- Broken Link
- Broken Link
- PatchThird Party Advisory
- ExploitRelease NotesVendor Advisory
- ExploitRelease NotesVendor Advisory
- Third Party Advisory
- Third Party Advisory
- PatchThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 19.2.1 (исключая)
cpe:2.3:a:twisted:twisted:*:*:*:*:*:*:*:*
Конфигурация 2
cpe:2.3:o:fedoraproject:fedora:29:*:*:*:*:*:*:*
Конфигурация 3
Одно из
cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:esm:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:19.10:*:*:*:*:*:*:*
Конфигурация 4
Одно из
cpe:2.3:a:oracle:zfs_storage_appliance_kit:8.8:*:*:*:*:*:*:*
cpe:2.3:o:oracle:solaris:11:*:*:*:*:*:*:*
EPSS
Процентиль: 67%
0.00531
Низкий
6.1 Medium
CVSS3
4.3 Medium
CVSS2
Дефекты
CWE-74
Связанные уязвимости
CVSS3: 6.1
ubuntu
больше 6 лет назад
In Twisted before 19.2.1, twisted.web did not validate or sanitize URIs or HTTP methods, allowing an attacker to inject invalid characters such as CRLF.
CVSS3: 6.5
redhat
больше 6 лет назад
In Twisted before 19.2.1, twisted.web did not validate or sanitize URIs or HTTP methods, allowing an attacker to inject invalid characters such as CRLF.
CVSS3: 6.1
debian
больше 6 лет назад
In Twisted before 19.2.1, twisted.web did not validate or sanitize URI ...
EPSS
Процентиль: 67%
0.00531
Низкий
6.1 Medium
CVSS3
4.3 Medium
CVSS2
Дефекты
CWE-74