Input validation error in Twisted Web - CVE-2019-12387

 

Input validation error in Twisted Web - CVE-2019-12387

Published: June 10, 2019 / Updated: July 17, 2020


Vulnerability identifier: #VU31043
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-12387
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

In Twisted before 19.2.1, twisted.web did not validate or sanitize URIs or HTTP methods, allowing an attacker to inject invalid characters such as CRLF.


Affected software

Twisted Web
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
SUSE OpenStack Cloud Crowbar
SUSE OpenStack Cloud
HPE Helion Openstack
SUSE Linux Enterprise Module for Web Scripting
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
Opensuse
SUSE Linux
Fedora
py3-twisted (Alpine package)
python-twisted-web (Red Hat package)
python-Twisted
python-Twisted-debuginfo
python-Twisted-debugsource
python-twisted

How to mitigate CVE-2019-12387

Install update from vendor's website.

Twisted Web - update to 19.2.1
py3-twisted (Alpine package) - update to 20.3.0-r0
python-twisted-web (Red Hat package) - update to 12.1.0-6.el7
python-Twisted - update to 15.2.1-9.23.1
python-Twisted-debuginfo - update to 15.2.1-9.23.1
python-Twisted-debugsource - update to 15.2.1-9.23.1
python-twisted - update to 18.9.0-2.fc29

External References

Related Security Bulletins