Cross-site scripting in Twisted Web - CVE-2022-39348
Published: October 31, 2022
Vulnerability details
The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied datawithin "NameVirtualHost". A remote user can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website.
Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.
Affected software
Amazon Linux AMI
Gentoo Linux
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Enterprise Storage
SUSE OpenStack Cloud Crowbar
HPE Helion Openstack
SUSE OpenStack Cloud
Oracle Solaris
SUSE Linux Enterprise Module for Web Scripting
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Module for Server Applications
openSUSE Leap
openEuler
Ubuntu
SUSE Linux Enterprise Module for Packagehub Subpackages
python-twisted-web
python-Twisted
python-Twisted-debuginfo
python-Twisted-debugsource
python3-twisted (Ubuntu package)
python3-Twisted-debuginfo
python-Twisted-doc
python2-Twisted
python2-Twisted-debuginfo
python3-Twisted
python-twisted-help
python3-twisted
python-twisted
dev-python/twisted
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
How to mitigate CVE-2022-39348
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.8.2
python-twisted-web - update to 8.2.0-6.8
python-Twisted - update to 15.2.1-9.23.1
python-Twisted-debuginfo - addressed in versions 15.2.1-9.23.1, 19.10.0-150200.3.18.1
python-Twisted-debugsource - addressed in versions 15.2.1-9.23.1, 19.10.0-150200.3.18.1
python3-twisted (Ubuntu package) - addressed in versions 18.9.0-11ubuntu0.20.04.3, 22.1.0-2ubuntu2.4, 22.4.0-4ubuntu0.23.04.1, 22.4.0-4ubuntu0.23.10.1
python3-Twisted-debuginfo - update to 19.10.0-150200.3.18.1
python-Twisted-doc - addressed in versions 19.10.0-150200.3.18.1, 22.2.0-150400.5.7.1
python2-Twisted - update to 19.10.0-150200.3.18.1
python2-Twisted-debuginfo - update to 19.10.0-150200.3.18.1
python3-Twisted - addressed in versions 19.10.0-150200.3.18.1, 22.2.0-150400.5.7.1
python-twisted-help - addressed in versions 22.4.0-1, 22.4.0-2
python3-twisted - addressed in versions 22.4.0-1, 22.4.0-2
python-twisted - addressed in versions 22.4.0-1, 22.4.0-2
python-twisted - update to 22.4.0-125
dev-python/twisted - update to 22.10.0
External References
Related Security Bulletins
- Cross-site scripting in Twisted
- SUSE update for python-Twisted
- SUSE update for python-Twisted
- SUSE update for python-Twisted
- Gentoo update for Twisted
- Amazon Linux AMI update for python-twisted-web
- Multiple vulnerabilities in Oracle Solaris third-party software
- Ubuntu update for twisted
- Cross-site scripting in IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
- openEuler 20.03 LTS SP3 update for python-twisted
- openEuler 22.03 LTS update for python-twisted
- openEuler 22.03 LTS SP1 update for python-twisted
- openEuler 22.03 LTS SP2 update for python-twisted
- openEuler 20.03 LTS SP4 update for python-twisted
- Amazon Linux AMI update for python-twisted