← Back

CVE-2019-12387

nvd nist
Published: Jun 10, 2019Modified: Nov 25, 2024

JSON object

Loading...
6.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: NVD

Description

In Twisted before 19.2.1, twisted.web did not validate or sanitize URIs or HTTP methods, allowing an attacker to inject invalid characters such as CRLF.

Affected (8)

Show all products
1 product
Twisted
1 product
Fedora
1 product
Ubuntu Linux
2 products
Solaris
Zfs Storage Appliance Kit
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 19.2.1
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 29
Configuration C
4 vulnerable
Vulnerable SoftwareAffected Versions
Canonical
Version 14.04
Version 16.04
Version 18.04
Version 19.10
Configuration D
2 vulnerable
Vulnerable SoftwareAffected Versions
Version 11
Version 8.8

References (18)

Source: cve@mitre.org
ExploitRelease NotesVendor Advisory
Source: cve@mitre.org
ExploitRelease NotesVendor Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitRelease NotesVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitRelease NotesVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory

Timeline

No history available yet.