UBUNTU-CVE-2022-21712
Dashboard / Vulnerabilities / UBUNTU-CVE-2022-21712
UBUNTU-CVE-2022-21712
Summary:
Details: twisted is an event-driven networking engine written in Python. In affected versions twisted exposes cookies and authorization headers when following cross-origin redirects. This issue is present in the `twited.web.RedirectAgent` and `twisted.web. BrowserLikeRedirectAgent` functions. Users are advised to upgrade. There are no known workarounds.
References: https://ubuntu.com/security/CVE-2022-21712, https://github.com/twisted/twisted/security/advisories/GHSA-92x2-jw7w-xvvx, https://github.com/twisted/twisted/releases/tag/twisted-22.1.0, https://ubuntu.com/security/notices/USN-5354-1, https://www.cve.org/CVERecord?id=CVE-2022-21712
Affected packages
Package
Name: twisted
Purl: pkg:deb/ubuntu/[email protected]+esm3?arch=source&distro=esm-infra-legacy/trusty
Affected ranges
Type: ECOSYSTEM
Events:
