7.5
CVSSv3

CVE-2022-21712

Published: 07/02/2022 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 446
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

It has been discovered that twisted before 22.1 exposes cookies and authorization headers when following cross-origin redirects. This issue is present in the `twited.web.RedirectAgent` and `twisted.web. BrowserLikeRedirectAgent` functions.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

twistedmatrix twisted

debian debian linux 9.0

fedoraproject fedora 35

fedoraproject fedora 36

Vendor Advisories

Several security issues were fixed in Twisted ...
Synopsis Important: Red Hat OpenStack Platform 161 (python-twisted) security update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for python-twisted is now available for Red Hat OpenStackPlatform 161 (Train) ...
Synopsis Important: Red Hat OpenStack Platform 162 (python-twisted) security update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for python-twisted is now available for Red Hat OpenStackPlatform 162 (Train) ...
It has been discovered that twisted prior to 221 exposes cookies and authorization headers when following cross-origin redirects This issue is present in the `twitedwebRedirectAgent` and `twistedweb BrowserLikeRedirectAgent` functions ...
ALAS-2022-231 Amazon Linux 2022 Security Advisory: ALAS-2022-231 Advisory Release Date: 2022-12-06 16:42 Pacific ...