Inconsistent interpretation of HTTP requests in Twisted Web - CVE-2020-10108
Published: March 24, 2020
Vulnerability details
The vulnerability allows a remote attacker to perform HTTP request smuggling attacks.
The vulnerability exists due to an error when processing two Content-length headers, sent within one HTTP request that caused the request body to be interpreted as a pipelined request. A remote attacker can send a specially crafted HTTP request to the affected web server and posing HTTP cache or perform other attacks against web application.
Affected software
Amazon Linux AMI
Gentoo Linux
Red Hat Enterprise Linux for Power, big endian
CentOS
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, little endian
Fedora
SUSE OpenStack Cloud Crowbar
SUSE OpenStack Cloud
HPE Helion Openstack
SUSE Linux Enterprise Module for Web Scripting
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
Synapse
python-twisted-web (Red Hat package)
py3-twisted (Alpine package)
python-Twisted
python-Twisted-debuginfo
python-Twisted-debugsource
python-twisted
How to mitigate CVE-2020-10108
Synapse - update to 1.12.0
python-twisted-web (Red Hat package) - addressed in versions 8.2.0-6.el6_10, 12.1.0-7.el7_8
py3-twisted (Alpine package) - update to 20.3.0-r0
python-Twisted - addressed in versions 15.2.1-9.20.1, 15.2.1-9.23.1
python-Twisted-debuginfo - addressed in versions 15.2.1-9.20.1, 15.2.1-9.23.1
python-Twisted-debugsource - addressed in versions 15.2.1-9.20.1, 15.2.1-9.23.1
python-twisted - addressed in versions 19.2.1-6.fc31, 19.10.0-2.el8, 19.10.0-2.fc32
External References
Related Security Bulletins
- Multiple vulnerabilities in Twisted Web
- Multiple vulnerabilities in Twisted Web component in Synapse
- Red Hat Enterprise Linux 6 update for python-twisted-web
- CentOS 6 update for python-twisted-web
- CentOS 7 update for python-twisted-web
- Amazon Linux AMI update for python-twisted-web
- Gentoo update for Twisted
- Inconsistent interpretation of HTTP requests in py3-twisted (Alpine package)
- SUSE update for python-Twisted
- SUSE update for python-Twisted
- Red Hat Enterprise Linux 7 update for python-twisted-web
- Fedora 32 update for python-twisted
- Fedora 31 update for python-twisted
- Fedora EPEL 8 update for python-twisted