QID 981937
QID 981937: Python (pip) Security Update for Twisted (GHSA-p5xh-vx83-mxcj)
In Twisted Web through 19.10.0, there was an HTTP request splitting vulnerability. When presented with a content-length and a chunked encoding header, the content-length took precedence and the remainder of the request body was interpreted as a pipelined request.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-p5xh-vx83-mxcj for updates pertaining to this vulnerability.
Vendor References
- GHSA-p5xh-vx83-mxcj -
github.com/advisories/GHSA-p5xh-vx83-mxcj
CVEs related to QID 981937
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-p5xh-vx83-mxcj | Twisted |
|