QID 355118
Date Published: 2023-05-29
QID 355118: Amazon Linux Security Advisory for python-twisted : ALAS2023-2023-056
A flaw was found in the twisted python library when webclient redirects via the redirectagent and browserlikeredirectagent methods.
This flaw allows an attacker to take advantage of these cross-origin redirects and leak the cookie and authorization headers. (
( CVE-2022-21712) an uncontrolled resource consumption flaw was found in python-twisted in the datareceived() function.
This flaw allows an unauthenticated, remote attacker to send a simple command to use all available memory and crash the server. (
( CVE-2022-21716) a flaw was found in python-twisted.
This vulnerability occurs due to the parsing of illegal constructs in the twisted.web.http module.
The illegal constructs include '+/-' in the content-length header, '\n and \t' etc.
Non-conformant parsing leads to a desync if requests pass through multiple http parsers.
This flaw allows a remote attacker to perform an http request smuggling attack. (
( CVE-2022-24801)
Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.
Successful exploitation of this vulnerability could lead to a securitybreach or could affect integrity, availability, and confidentiality.
- ALAS2023-2023-056 -
alas.aws.amazon.com/AL2023/ALAS-2023-056.html
CVEs related to QID 355118
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| ALAS2023-2023-056 | amazon linux 2023 |
|