Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 11

Количество 11

fstec логотип

BDU:2024-01299

почти 3 года назад

Уязвимость компонента twisted.web сетевого фреймворка Twisted, позволяющая нарушителю оказать воздействие на целостность защищаемой информации

CVSS3: 5.3
EPSS: Низкий
redos логотип

ROS-20250905-02

11 месяцев назад

Уязвимость python3-twisted

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2023-46137

почти 3 года назад

Twisted is an event-based framework for internet applications. Prior to version 23.10.0rc1, when sending multiple HTTP requests in one TCP packet, twisted.web will process the requests asynchronously without guaranteeing the response order. If one of the endpoints is controlled by an attacker, the attacker can delay the response on purpose to manipulate the response of the second request when a victim launched two requests using HTTP pipeline. Version 23.10.0rc1 contains a patch for this issue.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2023-46137

почти 3 года назад

Twisted is an event-based framework for internet applications. Prior to version 23.10.0rc1, when sending multiple HTTP requests in one TCP packet, twisted.web will process the requests asynchronously without guaranteeing the response order. If one of the endpoints is controlled by an attacker, the attacker can delay the response on purpose to manipulate the response of the second request when a victim launched two requests using HTTP pipeline. Version 23.10.0rc1 contains a patch for this issue.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2023-46137

почти 3 года назад

Twisted is an event-based framework for internet applications. Prior to version 23.10.0rc1, when sending multiple HTTP requests in one TCP packet, twisted.web will process the requests asynchronously without guaranteeing the response order. If one of the endpoints is controlled by an attacker, the attacker can delay the response on purpose to manipulate the response of the second request when a victim launched two requests using HTTP pipeline. Version 23.10.0rc1 contains a patch for this issue.

CVSS3: 5.3
EPSS: Низкий
msrc логотип

CVE-2023-46137

больше 1 года назад

twisted.web has disordered HTTP pipeline response

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2023-46137

почти 3 года назад

Twisted is an event-based framework for internet applications. Prior t ...

CVSS3: 5.3
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:4830-1

больше 2 лет назад

Security update for python-Twisted

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:4608-1

больше 2 лет назад

Security update for python-Twisted

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:4607-1

больше 2 лет назад

Security update for python3-Twisted

EPSS: Низкий
github логотип

GHSA-xc8x-vp79-p3wm

почти 3 года назад

twisted.web has disordered HTTP pipeline response

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2024-01299

Уязвимость компонента twisted.web сетевого фреймворка Twisted, позволяющая нарушителю оказать воздействие на целостность защищаемой информации

CVSS3: 5.3
1%
Низкий
почти 3 года назад
redos логотип
ROS-20250905-02

Уязвимость python3-twisted

CVSS3: 5.3
1%
Низкий
11 месяцев назад
ubuntu логотип
CVE-2023-46137

Twisted is an event-based framework for internet applications. Prior to version 23.10.0rc1, when sending multiple HTTP requests in one TCP packet, twisted.web will process the requests asynchronously without guaranteeing the response order. If one of the endpoints is controlled by an attacker, the attacker can delay the response on purpose to manipulate the response of the second request when a victim launched two requests using HTTP pipeline. Version 23.10.0rc1 contains a patch for this issue.

CVSS3: 5.3
1%
Низкий
почти 3 года назад
redhat логотип
CVE-2023-46137

Twisted is an event-based framework for internet applications. Prior to version 23.10.0rc1, when sending multiple HTTP requests in one TCP packet, twisted.web will process the requests asynchronously without guaranteeing the response order. If one of the endpoints is controlled by an attacker, the attacker can delay the response on purpose to manipulate the response of the second request when a victim launched two requests using HTTP pipeline. Version 23.10.0rc1 contains a patch for this issue.

CVSS3: 5.3
1%
Низкий
почти 3 года назад
nvd логотип
CVE-2023-46137

Twisted is an event-based framework for internet applications. Prior to version 23.10.0rc1, when sending multiple HTTP requests in one TCP packet, twisted.web will process the requests asynchronously without guaranteeing the response order. If one of the endpoints is controlled by an attacker, the attacker can delay the response on purpose to manipulate the response of the second request when a victim launched two requests using HTTP pipeline. Version 23.10.0rc1 contains a patch for this issue.

CVSS3: 5.3
1%
Низкий
почти 3 года назад
msrc логотип
CVE-2023-46137

twisted.web has disordered HTTP pipeline response

CVSS3: 5.3
1%
Низкий
больше 1 года назад
debian логотип
CVE-2023-46137

Twisted is an event-based framework for internet applications. Prior t ...

CVSS3: 5.3
1%
Низкий
почти 3 года назад
suse-cvrf логотип
SUSE-SU-2023:4830-1

Security update for python-Twisted

1%
Низкий
больше 2 лет назад
suse-cvrf логотип
SUSE-SU-2023:4608-1

Security update for python-Twisted

1%
Низкий
больше 2 лет назад
suse-cvrf логотип
SUSE-SU-2023:4607-1

Security update for python3-Twisted

1%
Низкий
больше 2 лет назад
github логотип
GHSA-xc8x-vp79-p3wm

twisted.web has disordered HTTP pipeline response

CVSS3: 5.3
1%
Низкий
почти 3 года назад

Уязвимостей на страницу