QID 355072
Date Published: 2023-05-18
QID 355072: Amazon Linux Security Advisory for python-twisted-web : AL2012-2023-396
Package updates are available for Amazon Linux that fix the following vulnerabilities:
CVE-2022-39348:
A host header injection flaw was found in the twisted event-based framework's web module. When the host header does not match a configured host, the web module will render unescaped characters into the 404 response. This can result in HTML and script injection. For this vulnerability to be exploited, the attacker needs to be in a privileged position.
2139431: CVE-2022-39348 python-twisted: NameVirtualHost Host header injection
CVE-2022-24801:
A flaw was found in python-twisted. This vulnerability occurs due to the parsing of illegal constructs in the twisted.web.http module. The illegal constructs include '+/-' in the Content-Length header, '\n and \t' etc. Non-conformant parsing leads to a desync if requests pass through multiple HTTP parsers. This flaw allows a remote attacker to perform an HTTP request smuggling attack.
2073114: CVE-2022-24801 python-twisted: possible http request smuggling
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
CVEs related to QID 355072
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| AL2012-2023-396 | Amazon Linux Bare Metal |
|