CVE-2019-12387

MEDIUM6.1EPSS 1.8%

Twisted CRLF Injection

發布日:2019/6/10修改日:2024/11/25
也稱為:GHSA-6cc5-2vg4-cc7mDEBIAN-CVE-2019-12387PYSEC-2019-128

描述

In Twisted before 19.2.1, twisted.web did not validate or sanitize URIs or HTTP methods, allowing an attacker to inject invalid characters such as CRLF.

受影響套件(3)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 4.0CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
osvCVSS 3.1MEDIUM6.1CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

參考連結(18)