QID 355072

Date Published: 2023-05-18

QID 355072: Amazon Linux Security Advisory for python-twisted-web : AL2012-2023-396

Package updates are available for Amazon Linux that fix the following vulnerabilities:
CVE-2022-39348:
A host header injection flaw was found in the twisted event-based framework's web module. When the host header does not match a configured host, the web module will render unescaped characters into the 404 response. This can result in HTML and script injection. For this vulnerability to be exploited, the attacker needs to be in a privileged position. 2139431: CVE-2022-39348 python-twisted: NameVirtualHost Host header injection CVE-2022-24801:
A flaw was found in python-twisted. This vulnerability occurs due to the parsing of illegal constructs in the twisted.web.http module. The illegal constructs include '+/-' in the Content-Length header, '\n and \t' etc. Non-conformant parsing leads to a desync if requests pass through multiple HTTP parsers. This flaw allows a remote attacker to perform an HTTP request smuggling attack. 2073114: CVE-2022-24801 python-twisted: possible http request smuggling

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as Critical - 8.1 severity.
  • CVSS V2 rated as High - 6.8 severity.
  • Solution
    Administrators are advised to apply the appropriate software updates.
    Vendor References

    CVEs related to QID 355072

    Software Advisories
    Advisory ID Software Component Link
    AL2012-2023-396 Amazon Linux Bare Metal URL Logo docs.aws.amazon.com/AWSEC2/latest/UserGuide/install-updates.html