Input validation error in Twisted Web - CVE-2019-12387
Published: June 10, 2019 / Updated: July 17, 2020
Vulnerability identifier: #VU31043
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-12387
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to read and manipulate data.
In Twisted before 19.2.1, twisted.web did not validate or sanitize URIs or HTTP methods, allowing an attacker to inject invalid characters such as CRLF.
Affected software
Twisted Web
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
SUSE OpenStack Cloud Crowbar
SUSE OpenStack Cloud
HPE Helion Openstack
SUSE Linux Enterprise Module for Web Scripting
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
Opensuse
SUSE Linux
Fedora
py3-twisted (Alpine package)
python-twisted-web (Red Hat package)
python-Twisted
python-Twisted-debuginfo
python-Twisted-debugsource
python-twisted
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
SUSE OpenStack Cloud Crowbar
SUSE OpenStack Cloud
HPE Helion Openstack
SUSE Linux Enterprise Module for Web Scripting
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
Opensuse
SUSE Linux
Fedora
py3-twisted (Alpine package)
python-twisted-web (Red Hat package)
python-Twisted
python-Twisted-debuginfo
python-Twisted-debugsource
python-twisted
How to mitigate CVE-2019-12387
Install update from vendor's website.
Twisted Web - update to 19.2.1
py3-twisted (Alpine package) - update to 20.3.0-r0
python-twisted-web (Red Hat package) - update to 12.1.0-6.el7
python-Twisted - update to 15.2.1-9.23.1
python-Twisted-debuginfo - update to 15.2.1-9.23.1
python-Twisted-debugsource - update to 15.2.1-9.23.1
python-twisted - update to 18.9.0-2.fc29
py3-twisted (Alpine package) - update to 20.3.0-r0
python-twisted-web (Red Hat package) - update to 12.1.0-6.el7
python-Twisted - update to 15.2.1-9.23.1
python-Twisted-debuginfo - update to 15.2.1-9.23.1
python-Twisted-debugsource - update to 15.2.1-9.23.1
python-twisted - update to 18.9.0-2.fc29
External References
- http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00030.html
- http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00042.html
- https://github.com/twisted/twisted/commit/6c61fc4503ae39ab8ecee52d10f10ee2c371d7e2
- https://labs.twistedmatrix.com/2019/06/twisted-1921-released.html
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2G5RPDQ4BNB336HL6WW5ZJ344MAWNN7N/
- https://twistedmatrix.com/pipermail/twisted-python/2019-June/032352.html
- https://usn.ubuntu.com/4308-1/
- https://usn.ubuntu.com/4308-2/
- https://www.oracle.com/security-alerts/cpuapr2020.html