Lack of data validation In twisted
Description
Twisted CRLF Injection In Twisted before 19.2.1, twisted.web did not validate or sanitize URIs or HTTP methods, allowing an attacker to inject invalid characters such as CRLF.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
pypi | 19.2.1 | ||
debian 13 | 18.9.0-7 | ||
debian 11 | 18.9.0-7 | ||
debian 12 | 18.9.0-7 | ||
debian 14 | 18.9.0-7 | ||
rpm rhel7 | 0:12.1.0-6.el7 | ||
rpm rhel6 | - | - |
Aliases
1. 2. 3. 4. 5. 6. 7.
References
1. 2. 3. 4. 5. 6. 7. 8. 9. 10. 11.