Логотип exploitDog
bind: "CVE-2023-46137"
Консоль
Логотип exploitDog

exploitDog

bind: "CVE-2023-46137"

Количество 11

Количество 11

ubuntu логотип

CVE-2023-46137

больше 2 лет назад

Twisted is an event-based framework for internet applications. Prior to version 23.10.0rc1, when sending multiple HTTP requests in one TCP packet, twisted.web will process the requests asynchronously without guaranteeing the response order. If one of the endpoints is controlled by an attacker, the attacker can delay the response on purpose to manipulate the response of the second request when a victim launched two requests using HTTP pipeline. Version 23.10.0rc1 contains a patch for this issue.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2023-46137

больше 2 лет назад

Twisted is an event-based framework for internet applications. Prior to version 23.10.0rc1, when sending multiple HTTP requests in one TCP packet, twisted.web will process the requests asynchronously without guaranteeing the response order. If one of the endpoints is controlled by an attacker, the attacker can delay the response on purpose to manipulate the response of the second request when a victim launched two requests using HTTP pipeline. Version 23.10.0rc1 contains a patch for this issue.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2023-46137

больше 2 лет назад

Twisted is an event-based framework for internet applications. Prior to version 23.10.0rc1, when sending multiple HTTP requests in one TCP packet, twisted.web will process the requests asynchronously without guaranteeing the response order. If one of the endpoints is controlled by an attacker, the attacker can delay the response on purpose to manipulate the response of the second request when a victim launched two requests using HTTP pipeline. Version 23.10.0rc1 contains a patch for this issue.

CVSS3: 5.3
EPSS: Низкий
msrc логотип

CVE-2023-46137

12 месяцев назад

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2023-46137

больше 2 лет назад

Twisted is an event-based framework for internet applications. Prior t ...

CVSS3: 5.3
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:4830-1

около 2 лет назад

Security update for python-Twisted

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:4608-1

около 2 лет назад

Security update for python-Twisted

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:4607-1

около 2 лет назад

Security update for python3-Twisted

EPSS: Низкий
github логотип

GHSA-xc8x-vp79-p3wm

больше 2 лет назад

twisted.web has disordered HTTP pipeline response

CVSS3: 5.3
EPSS: Низкий
fstec логотип

BDU:2024-01299

больше 2 лет назад

Уязвимость компонента twisted.web сетевого фреймворка Twisted, позволяющая нарушителю оказать воздействие на целостность защищаемой информации

CVSS3: 5.3
EPSS: Низкий
redos логотип

ROS-20250905-02

5 месяцев назад

Уязвимость python3-twisted

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2023-46137

Twisted is an event-based framework for internet applications. Prior to version 23.10.0rc1, when sending multiple HTTP requests in one TCP packet, twisted.web will process the requests asynchronously without guaranteeing the response order. If one of the endpoints is controlled by an attacker, the attacker can delay the response on purpose to manipulate the response of the second request when a victim launched two requests using HTTP pipeline. Version 23.10.0rc1 contains a patch for this issue.

CVSS3: 5.3
1%
Низкий
больше 2 лет назад
redhat логотип
CVE-2023-46137

Twisted is an event-based framework for internet applications. Prior to version 23.10.0rc1, when sending multiple HTTP requests in one TCP packet, twisted.web will process the requests asynchronously without guaranteeing the response order. If one of the endpoints is controlled by an attacker, the attacker can delay the response on purpose to manipulate the response of the second request when a victim launched two requests using HTTP pipeline. Version 23.10.0rc1 contains a patch for this issue.

CVSS3: 5.3
1%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-46137

Twisted is an event-based framework for internet applications. Prior to version 23.10.0rc1, when sending multiple HTTP requests in one TCP packet, twisted.web will process the requests asynchronously without guaranteeing the response order. If one of the endpoints is controlled by an attacker, the attacker can delay the response on purpose to manipulate the response of the second request when a victim launched two requests using HTTP pipeline. Version 23.10.0rc1 contains a patch for this issue.

CVSS3: 5.3
1%
Низкий
больше 2 лет назад
msrc логотип
CVSS3: 5.3
1%
Низкий
12 месяцев назад
debian логотип
CVE-2023-46137

Twisted is an event-based framework for internet applications. Prior t ...

CVSS3: 5.3
1%
Низкий
больше 2 лет назад
suse-cvrf логотип
SUSE-SU-2023:4830-1

Security update for python-Twisted

1%
Низкий
около 2 лет назад
suse-cvrf логотип
SUSE-SU-2023:4608-1

Security update for python-Twisted

1%
Низкий
около 2 лет назад
suse-cvrf логотип
SUSE-SU-2023:4607-1

Security update for python3-Twisted

1%
Низкий
около 2 лет назад
github логотип
GHSA-xc8x-vp79-p3wm

twisted.web has disordered HTTP pipeline response

CVSS3: 5.3
1%
Низкий
больше 2 лет назад
fstec логотип
BDU:2024-01299

Уязвимость компонента twisted.web сетевого фреймворка Twisted, позволяющая нарушителю оказать воздействие на целостность защищаемой информации

CVSS3: 5.3
1%
Низкий
больше 2 лет назад
redos логотип
ROS-20250905-02

Уязвимость python3-twisted

CVSS3: 5.3
1%
Низкий
5 месяцев назад

Уязвимостей на страницу