Inconsistent interpretation of HTTP requests in Twisted Web - CVE-2022-24801
Published: April 12, 2022
Vulnerability details
The vulnerability allows a remote attacker to preform HTTP request smuggling attacks.
The vulnerability exists due to improper validation of HTTP requests within the twisted.web.http module. A remote attacker can send a specially crafted HTTP request to the server and smuggle arbitrary HTTP headers.
Successful exploitation of vulnerability may allow an attacker to poison HTTP cache and perform phishing attacks.
Affected software
Amazon Linux AMI
SUSE Manager Server
SUSE Manager Proxy
Anolis OS
CentOS
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for IBM z Systems
SUSE OpenStack Cloud Crowbar
SUSE OpenStack Cloud
Fedora
HPE Helion Openstack
Oracle Solaris
SUSE Linux Enterprise Module for Web Scripting
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Realtime Extension
SUSE Linux Enterprise Module for Server Applications
openSUSE Leap
openEuler
Ubuntu
Red Hat OpenShift Container Platform
Oracle ZFS Storage Appliance Kit
SUSE Linux Enterprise Module for Packagehub Subpackages
python-twisted (Red Hat package)
python-twisted-web
python-twisted-web (Red Hat package)
python-Twisted-debugsource
python-Twisted-debuginfo
python-Twisted
python-twisted
python-Twisted-doc
python3-Twisted-debuginfo
python2-Twisted-debuginfo
python2-Twisted
python3-Twisted
python3-twisted (Ubuntu package)
python3-twisted
python-twisted-help
Red Hat OpenStack Director Deployment Tools
Red Hat OpenStack
Red Hat OpenStack for IBM Power
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
PowerStore T
How to mitigate CVE-2022-24801
Red Hat OpenShift Container Platform - addressed in versions 4.9.54, 4.10.13
python-twisted (Red Hat package) - update to 16.4.1-20.el8ost
PowerStore T - update to 3.5.0.1-2083289
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.5.1
python-twisted-web - update to 8.2.0-6.8
python-twisted-web - update to 12.1.0-8
python-twisted-web (Red Hat package) - update to 12.1.0-8.el7_9
python-Twisted-debugsource - addressed in versions 15.2.1-9.14.1, 19.10.0-150200.3.9.1
python-Twisted-debuginfo - addressed in versions 15.2.1-9.14.1, 19.10.0-150200.3.9.1
python-Twisted - update to 15.2.1-9.14.1
python-twisted - addressed in versions 19.10.0-4.el8, 22.4.0-1.fc35, 22.4.0-1.fc36, 22.4.0-1.fc37
python-Twisted-doc - update to 19.10.0-150200.3.9.1
python3-Twisted-debuginfo - update to 19.10.0-150200.3.9.1
python2-Twisted-debuginfo - update to 19.10.0-150200.3.9.1
python2-Twisted - update to 19.10.0-150200.3.9.1
python3-Twisted - update to 19.10.0-150200.3.9.1
python3-twisted (Ubuntu package) - update to 22.1.0-2ubuntu2.3
python3-twisted - update to 22.4.0-1
python-twisted-help - update to 22.4.0-1
python-twisted - update to 22.4.0-1
python-twisted - update to 22.4.0-124
External References
Related Security Bulletins
- HTTP request smuggling in Twisted Web
- Red Hat OpenStack Platform 16.2 update for python-twisted
- Red Hat OpenStack Platform 16.1 update for python-twisted
- Multiple vulnerabilities in OpenShift Container Platform 4.10
- Red Hat Enterprise Linux 7 update for python-twisted-web
- Multiple vulnerabilities in Oracle ZFS Storage Appliance Kit
- Multiple vulnerabilities in Oracle Solaris
- CentOS 7 update for python-twisted-web
- HTTP request smuggling in IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
- Ubuntu update for twisted
- Multiple vulnerabilities in OpenShift Container Platform 4.9
- SUSE update for python-Twisted
- SUSE update for python-Twisted
- Amazon Linux AMI update for python-twisted-web
- Multiple vulnerabilities in Dell PowerStore Family
- Fedora EPEL 8 update for python-twisted
- openEuler 20.03 LTS SP3 update for python-twisted
- openEuler 22.03 LTS update for python-twisted
- openEuler 20.03 LTS SP4 update for python-twisted
- Amazon Linux AMI update for python-twisted
- Fedora 37 update for python-twisted
- Fedora 36 update for python-twisted
- Fedora 35 update for python-twisted
- Anolis OS update for python-twisted-web