Описание
twisted is an event-driven networking engine written in Python. In affected versions twisted exposes cookies and authorization headers when following cross-origin redirects. This issue is present in the twited.web.RedirectAgent and twisted.web. BrowserLikeRedirectAgent functions. Users are advised to upgrade. There are no known workarounds.
A flaw was found in the twisted Python library when WebClient redirects via the RedirectAgent and BrowserLikeRedirectAgent methods. This flaw allows an attacker to take advantage of these cross-origin redirects and leak the cookie and authorization headers.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Ansible Automation Platform 1.2 | twisted[tls] | Affected | ||
| Red Hat Ansible Automation Platform 2 | twisted[tls] | Affected | ||
| Red Hat Ceph Storage 3 | python-twisted-core | Out of support scope | ||
| Red Hat Enterprise Linux 6 | python-twisted | Out of support scope | ||
| Red Hat OpenStack Platform 13 (Queens) | python-twisted | Out of support scope | ||
| Red Hat Satellite 6 | python-twisted | Will not fix | ||
| Red Hat Storage 3 | python-twisted-core | Affected | ||
| Service Telemetry Framework 1.3 for RHEL 8 | python-twisted | Will not fix | ||
| Red Hat OpenStack Platform 16.1 | python-twisted | Fixed | RHSA-2022:0982 | 24.03.2022 |
| Red Hat OpenStack Platform 16.2 | python-twisted | Fixed | RHSA-2022:0992 | 23.03.2022 |
Показывать по
Дополнительная информация
Статус:
EPSS
7.5 High
CVSS3
Связанные уязвимости
twisted is an event-driven networking engine written in Python. In affected versions twisted exposes cookies and authorization headers when following cross-origin redirects. This issue is present in the `twited.web.RedirectAgent` and `twisted.web. BrowserLikeRedirectAgent` functions. Users are advised to upgrade. There are no known workarounds.
twisted is an event-driven networking engine written in Python. In affected versions twisted exposes cookies and authorization headers when following cross-origin redirects. This issue is present in the `twited.web.RedirectAgent` and `twisted.web. BrowserLikeRedirectAgent` functions. Users are advised to upgrade. There are no known workarounds.
twisted is an event-driven networking engine written in Python. In aff ...
EPSS
7.5 High
CVSS3