CVE-2019-12387

CWE-74CWE-93CWE-11314 documents8 sources
Severity
6.1MEDIUM
EPSS
0.5%
top 33.16%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 10
Latest updateMar 30

Description

In Twisted before 19.2.1, twisted.web did not validate or sanitize URIs or HTTP methods, allowing an attacker to inject invalid characters such as CRLF.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages6 packages

PyPItwisted< 19.2.1
NVDtwisted/twisted< 19.2.1
Debiantwisted< 18.9.0-7+3
Ubuntutwisted< 16.0.0-1ubuntu0.4+2

Also affects: Fedora 29, Ubuntu Linux 14.04, 16.04, 18.04, 19.10

Patches

🔴Vulnerability Details

6
OSV
twisted vulnerabilities2020-03-30
OSV
twisted vulnerabilities2020-03-19
GHSA
Twisted CRLF Injection2019-06-10
OSV
Twisted CRLF Injection2019-06-10
OSV
CVE-2019-12387: In Twisted before 192019-06-10

📋Vendor Advisories

4
Ubuntu
Twisted vulnerabilities2020-03-30
Ubuntu
Twisted vulnerabilities2020-03-19
Red Hat
python-twisted: Improper neutralization of CRLF characters in URIs and HTTP methods2019-06-10
Debian
CVE-2019-12387: twisted - In Twisted before 19.2.1, twisted.web did not validate or sanitize URIs or HTTP ...2019

💬Community

3
Bugzilla
CVE-2019-12387 python-twisted: Improper neutralization of CRLF characters in URIs and HTTP methods [fedora-all]2019-06-12
Bugzilla
CVE-2019-12387 python-twisted: Improper neutralization of CRLF characters in URIs and HTTP methods [openstack-rdo]2019-06-12
Bugzilla
CVE-2019-12387 python-twisted: Improper neutralization of CRLF characters in URIs and HTTP methods2019-06-12
CVE-2019-12387 (MEDIUM CVSS 6.1) | In Twisted before 19.2.1 | cvebase.io