QID 981712

QID 981712: Python (pip) Security Update for twisted (GHSA-3gqj-cmxr-p4x2)

Twisted before 16.3.1 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect a CGI application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, aka an "httpoxy" issue.

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as Medium - 5.3 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Customers are advised to refer to GHSA-3gqj-cmxr-p4x2 for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 981712

    Software Advisories
    Advisory ID Software Component Link
    GHSA-3gqj-cmxr-p4x2 twisted URL Logo github.com/advisories/GHSA-3gqj-cmxr-p4x2