Описание
In Twisted before 19.2.1, twisted.web did not validate or sanitize URIs or HTTP methods, allowing an attacker to inject invalid characters such as CRLF.
Отчет
- This issue does not affect Red Hat Gluster Storage 3 and Red Hat Ceph Storage 2 and 3 because these products do not use the twisted web APIs.
- This issue does affect Red Hat Enterprise Linux 6. However, because this version is now in Maintenance Support 2 Phase and the flaw has a security impact of Moderate, it is not currently planned to be addressed in future Red Hat Enterprise Linux 6 updates. For additional information, refer to the Red Hat Enterprise Linux Life Cycle: https://access.redhat.com/support/policy/updates/errata
- In Red Hat OpenStack Platform, because the flaw has a lower impact and the fix would require a substantial amount of development, no update will be provided at this time for the RHOSP python-twisted package.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Ceph Storage 2 | calamari-server | Will not fix | ||
| Red Hat Ceph Storage 2 | python-twisted-core | Not affected | ||
| Red Hat Ceph Storage 3 | python-twisted-core | Not affected | ||
| Red Hat Enterprise Linux 6 | python-twisted-web | Will not fix | ||
| Red Hat OpenStack Platform 10 (Newton) | python-twisted | Will not fix | ||
| Red Hat OpenStack Platform 13 (Queens) | python-twisted | Will not fix | ||
| Red Hat OpenStack Platform 14 (Rocky) | python-twisted | Will not fix | ||
| Red Hat OpenStack Platform 9 (Mitaka) | python-twisted | Will not fix | ||
| Red Hat OpenStack Platform 9 (Mitaka) Operational Tools | python-twisted-core | Not affected | ||
| Red Hat Storage 3 | python-twisted-core | Not affected |
Показывать по
10
Дополнительная информация
Статус:
Moderate
Дефект:
CWE-113
https://bugzilla.redhat.com/show_bug.cgi?id=1719501python-twisted: Improper neutralization of CRLF characters in URIs and HTTP methods
EPSS
Процентиль: 83%
0.02523
Низкий
6.5 Medium
CVSS3
Связанные уязвимости
CVSS3: 6.1
ubuntu
около 7 лет назад
In Twisted before 19.2.1, twisted.web did not validate or sanitize URIs or HTTP methods, allowing an attacker to inject invalid characters such as CRLF.
CVSS3: 6.1
nvd
около 7 лет назад
In Twisted before 19.2.1, twisted.web did not validate or sanitize URIs or HTTP methods, allowing an attacker to inject invalid characters such as CRLF.
CVSS3: 6.1
debian
около 7 лет назад
In Twisted before 19.2.1, twisted.web did not validate or sanitize URI ...
EPSS
Процентиль: 83%
0.02523
Низкий
6.5 Medium
CVSS3