CVE-2019-12387

MEDIUM6.1EPSS 1.8%

Twisted CRLF Injection

Published: 6/10/2019Modified: 11/25/2024
Also known as:GHSA-6cc5-2vg4-cc7mDEBIAN-CVE-2019-12387PYSEC-2019-128

Description

In Twisted before 19.2.1, twisted.web did not validate or sanitize URIs or HTTP methods, allowing an attacker to inject invalid characters such as CRLF.

Affected packages (3)

CVSS scores

SourceVersionSeverityVector
osvCVSS 4.0CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
osvCVSS 3.1MEDIUM6.1CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

References (18)