Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-41810

Опубликовано: 29 июл. 2024
Источник: redhat
CVSS3: 4.2
EPSS Средний

Описание

Twisted is an event-based framework for internet applications, supporting Python 3.6+. The twisted.web.util.redirectTo function contains an HTML injection vulnerability. If application code allows an attacker to control the redirect URL this vulnerability may result in Reflected Cross-Site Scripting (XSS) in the redirect response HTML body. This vulnerability is fixed in 24.7.0rc1.

A Cross-site scripting (XSS) vulnerability exists in Python-Twisted in the twisted.web.util.redirectTo function. This flaw allows an attacker to control the redirect URL, leading to reflected XSS in the HTML body of the redirect response. If exploited, a remote attacker could inject malicious HTML, causing unauthorized JavaScript execution within the victim's browser session. This issue can result in unauthorized access to the victim’s account and data or allow the attacker to perform operations on behalf of the victim.

Отчет

The vulnerability is exploitable only in Firefox. All other tested browsers will display an error message to the user and will not render the HTML body.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ansible Automation Platform 1.2ansible-towerWill not fix
Red Hat Ansible Automation Platform 2python3x-twistedAffected
Red Hat Ansible Automation Platform 2python-twistedAffected
Red Hat Enterprise Linux 6python-twistedOut of support scope
Red Hat Enterprise Linux 6python-twisted-webOut of support scope
Red Hat Enterprise Linux 7python-twisted-webOut of support scope
Red Hat OpenStack Platform 16.1python-twistedOut of support scope
Red Hat OpenStack Platform 16.2python-twistedWill not fix
Red Hat Storage 3python-carbonAffected
Red Hat Ansible Automation Platform 2.4 for RHEL 8automation-controllerFixedRHSA-2024:731227.09.2024

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-79
Дефект:
CWE-80
https://bugzilla.redhat.com/show_bug.cgi?id=2300497python-twisted: Reflected XSS via HTML Injection in Redirect Response

EPSS

Процентиль: 99%
0.68165
Средний

4.2 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.1
ubuntu
больше 1 года назад

Twisted is an event-based framework for internet applications, supporting Python 3.6+. The `twisted.web.util.redirectTo` function contains an HTML injection vulnerability. If application code allows an attacker to control the redirect URL this vulnerability may result in Reflected Cross-Site Scripting (XSS) in the redirect response HTML body. This vulnerability is fixed in 24.7.0rc1.

CVSS3: 6.1
nvd
больше 1 года назад

Twisted is an event-based framework for internet applications, supporting Python 3.6+. The `twisted.web.util.redirectTo` function contains an HTML injection vulnerability. If application code allows an attacker to control the redirect URL this vulnerability may result in Reflected Cross-Site Scripting (XSS) in the redirect response HTML body. This vulnerability is fixed in 24.7.0rc1.

CVSS3: 6.1
msrc
больше 1 года назад

Описание отсутствует

CVSS3: 6.1
debian
больше 1 года назад

Twisted is an event-based framework for internet applications, support ...

CVSS3: 6.1
github
больше 1 года назад

Twisted vulnerable to HTML injection in HTTP redirect body

EPSS

Процентиль: 99%
0.68165
Средний

4.2 Medium

CVSS3

Уязвимость CVE-2024-41810