#VU61611 Origin validation error in Twisted Web - CVE-2022-21712
Published: March 24, 2022
Twisted Web
Twisted Matrix Labs
Description
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to origin validation error in the "twited.web.RedirectAgent" and "twisted.web.BrowserLikeRedirectAgent" functions. A remote attacker attacker can trick the victim to click on a specially crafted link and obtain cookies and authorization headers.