CVE-2024-41671

Twisted is an event-based framework for internet applications, supporting Python 3.6+. The HTTP 1.0 and 1.1 server provided by twisted.web could process pipelined HTTP requests out-of-order, possibly resulting in information disclosure. This vulnerability is fixed in 24.7.0rc1.
Configurations

No configuration.

History

21 Nov 2024, 09:32

Type Values Removed Values Added
Summary
  • (es) Twisted es un framework basado en eventos para aplicaciones de Internet, compatible con Python 3.6+. El servidor HTTP 1.0 y 1.1 proporcionado por twisted.web podría procesar solicitudes HTTP canalizadas desordenadas, lo que posiblemente resulte en la divulgación de información. Esta vulnerabilidad se soluciona en 24.7.0rc1.
References
  • () https://www.vicarius.io/vsociety/posts/disordered-http-pipeline-in-twistedweb-cve-2024-4167 -
References () https://github.com/twisted/twisted/commit/046a164f89a0f08d3239ecebd750360f8914df33 - () https://github.com/twisted/twisted/commit/046a164f89a0f08d3239ecebd750360f8914df33 -
References () https://github.com/twisted/twisted/commit/4a930de12fb67e88fefcb8822104152f42b27abc - () https://github.com/twisted/twisted/commit/4a930de12fb67e88fefcb8822104152f42b27abc -
References () https://github.com/twisted/twisted/security/advisories/GHSA-c8m8-j448-xjx7 - () https://github.com/twisted/twisted/security/advisories/GHSA-c8m8-j448-xjx7 -

29 Jul 2024, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-29 15:15

Updated : 2024-11-21 09:32


NVD link : CVE-2024-41671

Mitre link : CVE-2024-41671

CVE.ORG link : CVE-2024-41671


JSON object : View

Products Affected

No product.

CWE
CWE-444

Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')