Количество 11
Количество 11
BDU:2024-01299
Уязвимость компонента twisted.web сетевого фреймворка Twisted, позволяющая нарушителю оказать воздействие на целостность защищаемой информации
ROS-20250905-02
Уязвимость python3-twisted
CVE-2023-46137
Twisted is an event-based framework for internet applications. Prior to version 23.10.0rc1, when sending multiple HTTP requests in one TCP packet, twisted.web will process the requests asynchronously without guaranteeing the response order. If one of the endpoints is controlled by an attacker, the attacker can delay the response on purpose to manipulate the response of the second request when a victim launched two requests using HTTP pipeline. Version 23.10.0rc1 contains a patch for this issue.
CVE-2023-46137
Twisted is an event-based framework for internet applications. Prior to version 23.10.0rc1, when sending multiple HTTP requests in one TCP packet, twisted.web will process the requests asynchronously without guaranteeing the response order. If one of the endpoints is controlled by an attacker, the attacker can delay the response on purpose to manipulate the response of the second request when a victim launched two requests using HTTP pipeline. Version 23.10.0rc1 contains a patch for this issue.
CVE-2023-46137
Twisted is an event-based framework for internet applications. Prior to version 23.10.0rc1, when sending multiple HTTP requests in one TCP packet, twisted.web will process the requests asynchronously without guaranteeing the response order. If one of the endpoints is controlled by an attacker, the attacker can delay the response on purpose to manipulate the response of the second request when a victim launched two requests using HTTP pipeline. Version 23.10.0rc1 contains a patch for this issue.
CVE-2023-46137
CVE-2023-46137
Twisted is an event-based framework for internet applications. Prior t ...
SUSE-SU-2023:4830-1
Security update for python-Twisted
SUSE-SU-2023:4608-1
Security update for python-Twisted
SUSE-SU-2023:4607-1
Security update for python3-Twisted
GHSA-xc8x-vp79-p3wm
twisted.web has disordered HTTP pipeline response
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
BDU:2024-01299 Уязвимость компонента twisted.web сетевого фреймворка Twisted, позволяющая нарушителю оказать воздействие на целостность защищаемой информации | CVSS3: 5.3 | 1% Низкий | около 2 лет назад | |
ROS-20250905-02 Уязвимость python3-twisted | CVSS3: 5.3 | 1% Низкий | 4 месяца назад | |
CVE-2023-46137 Twisted is an event-based framework for internet applications. Prior to version 23.10.0rc1, when sending multiple HTTP requests in one TCP packet, twisted.web will process the requests asynchronously without guaranteeing the response order. If one of the endpoints is controlled by an attacker, the attacker can delay the response on purpose to manipulate the response of the second request when a victim launched two requests using HTTP pipeline. Version 23.10.0rc1 contains a patch for this issue. | CVSS3: 5.3 | 1% Низкий | около 2 лет назад | |
CVE-2023-46137 Twisted is an event-based framework for internet applications. Prior to version 23.10.0rc1, when sending multiple HTTP requests in one TCP packet, twisted.web will process the requests asynchronously without guaranteeing the response order. If one of the endpoints is controlled by an attacker, the attacker can delay the response on purpose to manipulate the response of the second request when a victim launched two requests using HTTP pipeline. Version 23.10.0rc1 contains a patch for this issue. | CVSS3: 5.3 | 1% Низкий | около 2 лет назад | |
CVE-2023-46137 Twisted is an event-based framework for internet applications. Prior to version 23.10.0rc1, when sending multiple HTTP requests in one TCP packet, twisted.web will process the requests asynchronously without guaranteeing the response order. If one of the endpoints is controlled by an attacker, the attacker can delay the response on purpose to manipulate the response of the second request when a victim launched two requests using HTTP pipeline. Version 23.10.0rc1 contains a patch for this issue. | CVSS3: 5.3 | 1% Низкий | около 2 лет назад | |
CVSS3: 5.3 | 1% Низкий | 11 месяцев назад | ||
CVE-2023-46137 Twisted is an event-based framework for internet applications. Prior t ... | CVSS3: 5.3 | 1% Низкий | около 2 лет назад | |
SUSE-SU-2023:4830-1 Security update for python-Twisted | 1% Низкий | около 2 лет назад | ||
SUSE-SU-2023:4608-1 Security update for python-Twisted | 1% Низкий | около 2 лет назад | ||
SUSE-SU-2023:4607-1 Security update for python3-Twisted | 1% Низкий | около 2 лет назад | ||
GHSA-xc8x-vp79-p3wm twisted.web has disordered HTTP pipeline response | CVSS3: 5.3 | 1% Низкий | около 2 лет назад |
Уязвимостей на страницу