Description
In Twisted Web through 19.10.0, there was an HTTP request splitting vulnerability. When presented with a content-length and a chunked encoding header, the content-length took precedence and the remainder of the request body was interpreted as a pipelined request.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-2145-1 | twisted security update |
Debian DLA |
DLA-2145-2 | twisted security update |
Debian DLA |
DLA-2927-1 | twisted security update |
EUVD |
EUVD-2020-0229 | In Twisted Web through 19.10.0, there was an HTTP request splitting vulnerability. When presented with a content-length and a chunked encoding header, the content-length took precedence and the remainder of the request body was interpreted as a pipelined request. |
Github GHSA |
GHSA-p5xh-vx83-mxcj | HTTP Request Smuggling in Twisted |
Ubuntu USN |
USN-4308-1 | Twisted vulnerabilities |
Ubuntu USN |
USN-4308-2 | Twisted vulnerabilities |
References
History
Mon, 25 Nov 2024 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Twisted
Twisted twisted |
|
| CPEs | cpe:2.3:a:twisted:twisted:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Twistedmatrix
Twistedmatrix twisted |
Twisted
Twisted twisted |
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T10:50:57.900Z
Reserved: 2020-03-05T00:00:00.000Z
Link: CVE-2020-10109
No data.
Status : Modified
Published: 2020-03-12T13:15:12.370
Modified: 2024-11-25T18:12:24.673
Link: CVE-2020-10109
OpenCVE Enrichment
No data.
Debian DLA
EUVD
Github GHSA
Ubuntu USN