CVE-2020-10109
Summary
| CVE | CVE-2020-10109 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-03-12 13:15:00 UTC |
| Updated | 2023-11-07 03:14:00 UTC |
| Description | In Twisted Web through 19.10.0, there was an HTTP request splitting vulnerability. When presented with a content-length and a chunked encoding header, the content-length took precedence and the remainder of the request body was interpreted as a pipelined request. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Twisted: Access restriction bypasses (GLSA 202007-24) — Gentoo security |
GENTOO |
security.gentoo.org |
|
| [SECURITY] Fedora 32 Update: python-twisted-19.10.0-2.fc32 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| Bishop Fox Advisories |
MISC |
know.bishopfox.com |
Exploit, Third Party Advisory |
| USN-4308-1: Twisted vulnerabilities | Ubuntu security notices | Ubuntu |
UBUNTU |
usn.ubuntu.com |
|
| [SECURITY] Fedora 32 Update: python-twisted-19.10.0-2.fc32 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| USN-4308-2: Twisted vulnerabilities | Ubuntu security notices | Ubuntu |
UBUNTU |
usn.ubuntu.com |
|
| [SECURITY] Fedora 31 Update: python-twisted-19.2.1-6.fc31 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] [DLA 2927-1] twisted security update |
MLIST |
lists.debian.org |
|
| [SECURITY] Fedora 31 Update: python-twisted-19.2.1-6.fc31 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| Twisted Version 19.10.0 |
MISC |
know.bishopfox.com |
Release Notes, Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 159768 Oracle Enterprise Linux Security Update for ol-automation-manager (ELSA-2022-9341)
- 179090 Debian Security Update for twisted (DLA 2927-1)
- 296073 Oracle Solaris 11.4 Support Repository Update (SRU) 24.75.2 Missing (CPUJUL2020)
- 501228 Alpine Linux Security Update for py3-twisted
- 505329 Alpine Linux Security Update for py3-twisted
- 752470 SUSE Enterprise Linux Security Update for python-Twisted (SUSE-SU-2022:2822-1)
- 900059 CBL-Mariner Linux Security Update for python-twisted 19.2.1
- 901514 Common Base Linux Mariner (CBL-Mariner) Security Update for python-twisted (6820-1)
- 902951 Common Base Linux Mariner (CBL-Mariner) Security Update for python-twisted (4687)
- 981937 Python (pip) Security Update for Twisted (GHSA-p5xh-vx83-mxcj)