Origin validation error in Twisted Web - CVE-2022-21712

 

Origin validation error in Twisted Web - CVE-2022-21712

Published: March 24, 2022


Vulnerability identifier: #VU61611
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-21712
CWE-ID: CWE-346
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to origin validation error in the "twited.web.RedirectAgent" and "twisted.web.BrowserLikeRedirectAgent" functions. A remote attacker attacker can trick the victim to click on a specially crafted link and obtain cookies and authorization headers.


Affected software

Twisted Web
Amazon Linux AMI
Gentoo Linux
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Enterprise Storage
SUSE OpenStack Cloud Crowbar
HPE Helion Openstack
SUSE OpenStack Cloud
Oracle Solaris
SUSE Linux Enterprise Module for Web Scripting
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Realtime Extension
SUSE Linux Enterprise Module for Server Applications
Ubuntu
openEuler
Fedora
SUSE Linux Enterprise Module for Packagehub Subpackages
python-twisted (Red Hat package)
python-Twisted
python-Twisted-debuginfo
python-Twisted-debugsource
python-twisted-bin (Ubuntu package)
python-twisted (Ubuntu package)
python3-twisted (Ubuntu package)
python3-twisted-bin (Ubuntu package)
python3-Twisted-debuginfo
python3-Twisted
python-twisted
python-twisted-help
python3-twisted
dev-python/twisted
Red Hat OpenStack for IBM Power
Red Hat OpenStack
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
Red Hat OpenStack Director Deployment Tools
PowerStore T

How to mitigate CVE-2022-21712

Install updates from vendor's website.

Twisted Web - update to 22.1.0
python-twisted (Red Hat package) - update to 16.4.1-19.el8ost
PowerStore T - update to 3.5.0.1-2083289
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.5.1
python-Twisted - addressed in versions 15.2.1-9.11.1, 15.2.1-9.23.1
python-Twisted-debuginfo - addressed in versions 15.2.1-9.11.1, 15.2.1-9.23.1, 19.10.0-3.6.1
python-Twisted-debugsource - addressed in versions 15.2.1-9.11.1, 15.2.1-9.23.1, 19.10.0-3.6.1
python-twisted-bin (Ubuntu package) - update to 17.9.0-2ubuntu0.3
python-twisted (Ubuntu package) - update to 17.9.0-2ubuntu0.3
python3-twisted (Ubuntu package) - addressed in versions 17.9.0-2ubuntu0.3, 18.9.0-11ubuntu0.20.04.2, 20.3.0-7ubuntu1.1
python3-twisted-bin (Ubuntu package) - addressed in versions 17.9.0-2ubuntu0.3, 18.9.0-11ubuntu0.20.04.2, 20.3.0-7ubuntu1.1
python3-Twisted-debuginfo - update to 19.10.0-3.6.1
python3-Twisted - update to 19.10.0-3.6.1
python-twisted - update to 22.4.0-1
python-twisted-help - update to 22.4.0-1
python3-twisted - update to 22.4.0-1
python-twisted - addressed in versions 22.4.0-1.fc35, 22.4.0-1.fc36, 22.4.0-1.fc37
python-twisted - update to 22.4.0-124
dev-python/twisted - update to 22.10.0

External References

Related Security Bulletins