cbcvebase.
CVE-2019-12387
published 2019-06-10

CVE-2019-12387: In Twisted before 19.2.1, twisted.web did not validate or sanitize URIs or HTTP methods, allowing an attacker to inject invalid characters such as CRLF.

PriorityP428medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
2.52%
83.1th percentile
In Twisted before 19.2.1, twisted.web did not validate or sanitize URIs or HTTP methods, allowing an attacker to inject invalid characters such as CRLF.

Affected

17 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiantwisted< twisted 18.9.0-7 (bookworm)twisted 18.9.0-7 (bookworm)
fedoraprojectfedora
oraclesolaris
oraclezfs_storage_appliance_kit
twistedtwisted< 19.2.119.2.1
twistedtwisted>= 0 < 18.9.0-718.9.0-7
twistedtwisted>= 0 < 18.9.0-718.9.0-7
twistedtwisted>= 0 < 18.9.0-718.9.0-7
twistedtwisted>= 0 < 18.9.0-718.9.0-7
twistedtwisted>= 0 < 19.2.119.2.1
twistedtwisted>= 0 < 16.0.0-1ubuntu0.416.0.0-1ubuntu0.4
twistedtwisted>= 0 < 17.9.0-2ubuntu0.117.9.0-2ubuntu0.1
twistedtwisted>= 0 < 13.2.0-1ubuntu1.2+esm113.2.0-1ubuntu1.2+esm1

CVSS provenance

nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv6.1MEDIUM
vendor_debian6.1MEDIUM
vendor_redhat6.1MEDIUM
vendor_ubuntu6.1MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.