Inconsistent interpretation of HTTP requests in Twisted Web - CVE-2020-10108

 

Inconsistent interpretation of HTTP requests in Twisted Web - CVE-2020-10108

Published: March 24, 2020


Vulnerability identifier: #VU26355
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-10108
CWE-ID: CWE-444
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform HTTP request smuggling attacks.

The vulnerability exists due to an error when processing two Content-length headers, sent within one HTTP request that caused the request body to be interpreted as a pipelined request. A remote attacker can send a specially crafted HTTP request to the affected web server and posing HTTP cache or perform other attacks against web application.


Affected software

Twisted Web
Amazon Linux AMI
Gentoo Linux
Red Hat Enterprise Linux for Power, big endian
CentOS
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, little endian
Fedora
SUSE OpenStack Cloud Crowbar
SUSE OpenStack Cloud
HPE Helion Openstack
SUSE Linux Enterprise Module for Web Scripting
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
Synapse
python-twisted-web (Red Hat package)
py3-twisted (Alpine package)
python-Twisted
python-Twisted-debuginfo
python-Twisted-debugsource
python-twisted

How to mitigate CVE-2020-10108

Install updates from vendor's website.

Twisted Web - update to 20.3.0
Synapse - update to 1.12.0
python-twisted-web (Red Hat package) - addressed in versions 8.2.0-6.el6_10, 12.1.0-7.el7_8
py3-twisted (Alpine package) - update to 20.3.0-r0
python-Twisted - addressed in versions 15.2.1-9.20.1, 15.2.1-9.23.1
python-Twisted-debuginfo - addressed in versions 15.2.1-9.20.1, 15.2.1-9.23.1
python-Twisted-debugsource - addressed in versions 15.2.1-9.20.1, 15.2.1-9.23.1
python-twisted - addressed in versions 19.2.1-6.fc31, 19.10.0-2.el8, 19.10.0-2.fc32

External References

Related Security Bulletins