CVE-2024-41671

high

Description

Twisted is an event-based framework for internet applications, supporting Python 3.6+. The HTTP 1.0 and 1.1 server provided by twisted.web could process pipelined HTTP requests out-of-order, possibly resulting in information disclosure. This vulnerability is fixed in 24.7.0rc1.

References

https://github.com/twisted/twisted/security/advisories/GHSA-c8m8-j448-xjx7

https://github.com/twisted/twisted/commit/4a930de12fb67e88fefcb8822104152f42b27abc

https://github.com/twisted/twisted/commit/046a164f89a0f08d3239ecebd750360f8914df33

Details

Source: Mitre, NVD

Published: 2024-07-29

Updated: 2024-07-29

Risk Information

CVSS v2

Base Score: 9

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:P/A:P

Severity: High

CVSS v3

Base Score: 8.3

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L

Severity: High