9.8

CVE-2020-10108

Exploit
In Twisted Web through 19.10.0, there was an HTTP request splitting vulnerability. When presented with two content-length headers, it ignored the first header. When the second content-length value was set to zero, the request body was interpreted as a pipelined request.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Twisted ≫ Twisted Version <= 19.10.0
Fedoraproject ≫ Fedora Version 31
Fedoraproject ≫ Fedora Version 32
Debian ≫ Debian Linux Version 9.0
Canonical ≫ Ubuntu Linux Version 14.04 SwEdition esm
Canonical ≫ Ubuntu Linux Version 16.04 SwEdition esm
Canonical ≫ Ubuntu Linux Version 18.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 19.10
Oracle ≫ Solaris Version 10
Oracle ≫ Solaris Version 11
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.97% 0.893
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
NIST 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')

The product acts as an intermediary HTTP agent (such as a proxy or firewall) in the data flow between two entities such as a client and server, but it does not interpret malformed HTTP requests or responses in ways that are consistent with how the messages will be processed by those entities that are at the ultimate destination.

https://www.oracle.com/security-alerts/cpuoct2020.html
Patch
Third Party Advisory
https://usn.ubuntu.com/4308-1/
Third Party Advisory
https://usn.ubuntu.com/4308-2/
Third Party Advisory
https://know.bishopfox.com/advisories
Third Party Advisory
Exploit
https://know.bishopfox.com/advisories/twisted-version-19.10.0
Third Party Advisory
Release Notes
https://lists.debian.org/debian-lts-announce/2022/02/msg00021.html
Third Party Advisory
Mailing List
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6ISMZFZBWW4EV6ETJGXAYIXN3AT7GBPL/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YW3NIL7VXSGJND2Q4BSXM3CFTAFU6T7D/
https://security.gentoo.org/glsa/202007-24
Third Party Advisory