Описание
Twisted is an event-based framework for internet applications, supporting Python 3.6+. The HTTP 1.0 and 1.1 server provided by twisted.web could process pipelined HTTP requests out-of-order, possibly resulting in information disclosure. This vulnerability is fixed in 24.7.0rc1.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | not-affected | 24.7.0-2 |
| esm-infra-legacy/trusty | not-affected | code not present |
| esm-infra/bionic | released | 17.9.0-2ubuntu0.3+esm2 |
| esm-infra/focal | released | 18.9.0-11ubuntu0.20.04.5 |
| esm-infra/xenial | not-affected | code not present |
| focal | released | 18.9.0-11ubuntu0.20.04.5 |
| jammy | released | 22.1.0-2ubuntu2.6 |
| noble | released | 24.3.0-1ubuntu0.1 |
| oracular | not-affected | 24.7.0-2 |
| trusty/esm | not-affected | code not present |
Показывать по
EPSS
8.3 High
CVSS3
Связанные уязвимости
Twisted is an event-based framework for internet applications, supporting Python 3.6+. The HTTP 1.0 and 1.1 server provided by twisted.web could process pipelined HTTP requests out-of-order, possibly resulting in information disclosure. This vulnerability is fixed in 24.7.0rc1.
Twisted is an event-based framework for internet applications, support ...
twisted.web has disordered HTTP pipeline response
Уязвимость компонента twisted.web сетевого фреймворка Twisted, позволяющая нарушителю раскрыть защищаемую информацию
EPSS
8.3 High
CVSS3