Логотип exploitDog
bind:"GHSA-xc8x-vp79-p3wm" OR bind:"CVE-2023-46137"
Консоль
Логотип exploitDog

exploitDog

bind:"GHSA-xc8x-vp79-p3wm" OR bind:"CVE-2023-46137"

Количество 11

Количество 11

github логотип

GHSA-xc8x-vp79-p3wm

около 2 лет назад

twisted.web has disordered HTTP pipeline response

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2023-46137

около 2 лет назад

Twisted is an event-based framework for internet applications. Prior to version 23.10.0rc1, when sending multiple HTTP requests in one TCP packet, twisted.web will process the requests asynchronously without guaranteeing the response order. If one of the endpoints is controlled by an attacker, the attacker can delay the response on purpose to manipulate the response of the second request when a victim launched two requests using HTTP pipeline. Version 23.10.0rc1 contains a patch for this issue.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2023-46137

около 2 лет назад

Twisted is an event-based framework for internet applications. Prior to version 23.10.0rc1, when sending multiple HTTP requests in one TCP packet, twisted.web will process the requests asynchronously without guaranteeing the response order. If one of the endpoints is controlled by an attacker, the attacker can delay the response on purpose to manipulate the response of the second request when a victim launched two requests using HTTP pipeline. Version 23.10.0rc1 contains a patch for this issue.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2023-46137

около 2 лет назад

Twisted is an event-based framework for internet applications. Prior to version 23.10.0rc1, when sending multiple HTTP requests in one TCP packet, twisted.web will process the requests asynchronously without guaranteeing the response order. If one of the endpoints is controlled by an attacker, the attacker can delay the response on purpose to manipulate the response of the second request when a victim launched two requests using HTTP pipeline. Version 23.10.0rc1 contains a patch for this issue.

CVSS3: 5.3
EPSS: Низкий
msrc логотип

CVE-2023-46137

11 месяцев назад

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2023-46137

около 2 лет назад

Twisted is an event-based framework for internet applications. Prior t ...

CVSS3: 5.3
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:4830-1

около 2 лет назад

Security update for python-Twisted

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:4608-1

около 2 лет назад

Security update for python-Twisted

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:4607-1

около 2 лет назад

Security update for python3-Twisted

EPSS: Низкий
fstec логотип

BDU:2024-01299

около 2 лет назад

Уязвимость компонента twisted.web сетевого фреймворка Twisted, позволяющая нарушителю оказать воздействие на целостность защищаемой информации

CVSS3: 5.3
EPSS: Низкий
redos логотип

ROS-20250905-02

4 месяца назад

Уязвимость python3-twisted

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xc8x-vp79-p3wm

twisted.web has disordered HTTP pipeline response

CVSS3: 5.3
1%
Низкий
около 2 лет назад
ubuntu логотип
CVE-2023-46137

Twisted is an event-based framework for internet applications. Prior to version 23.10.0rc1, when sending multiple HTTP requests in one TCP packet, twisted.web will process the requests asynchronously without guaranteeing the response order. If one of the endpoints is controlled by an attacker, the attacker can delay the response on purpose to manipulate the response of the second request when a victim launched two requests using HTTP pipeline. Version 23.10.0rc1 contains a patch for this issue.

CVSS3: 5.3
1%
Низкий
около 2 лет назад
redhat логотип
CVE-2023-46137

Twisted is an event-based framework for internet applications. Prior to version 23.10.0rc1, when sending multiple HTTP requests in one TCP packet, twisted.web will process the requests asynchronously without guaranteeing the response order. If one of the endpoints is controlled by an attacker, the attacker can delay the response on purpose to manipulate the response of the second request when a victim launched two requests using HTTP pipeline. Version 23.10.0rc1 contains a patch for this issue.

CVSS3: 5.3
1%
Низкий
около 2 лет назад
nvd логотип
CVE-2023-46137

Twisted is an event-based framework for internet applications. Prior to version 23.10.0rc1, when sending multiple HTTP requests in one TCP packet, twisted.web will process the requests asynchronously without guaranteeing the response order. If one of the endpoints is controlled by an attacker, the attacker can delay the response on purpose to manipulate the response of the second request when a victim launched two requests using HTTP pipeline. Version 23.10.0rc1 contains a patch for this issue.

CVSS3: 5.3
1%
Низкий
около 2 лет назад
msrc логотип
CVSS3: 5.3
1%
Низкий
11 месяцев назад
debian логотип
CVE-2023-46137

Twisted is an event-based framework for internet applications. Prior t ...

CVSS3: 5.3
1%
Низкий
около 2 лет назад
suse-cvrf логотип
SUSE-SU-2023:4830-1

Security update for python-Twisted

1%
Низкий
около 2 лет назад
suse-cvrf логотип
SUSE-SU-2023:4608-1

Security update for python-Twisted

1%
Низкий
около 2 лет назад
suse-cvrf логотип
SUSE-SU-2023:4607-1

Security update for python3-Twisted

1%
Низкий
около 2 лет назад
fstec логотип
BDU:2024-01299

Уязвимость компонента twisted.web сетевого фреймворка Twisted, позволяющая нарушителю оказать воздействие на целостность защищаемой информации

CVSS3: 5.3
1%
Низкий
около 2 лет назад
redos логотип
ROS-20250905-02

Уязвимость python3-twisted

CVSS3: 5.3
1%
Низкий
4 месяца назад

Уязвимостей на страницу