Cross-site scripting in Twisted Web - CVE-2022-39348

 

Cross-site scripting in Twisted Web - CVE-2022-39348

Published: October 31, 2022


Vulnerability identifier: #VU68855
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: CVE-2022-39348
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.

The vulnerability exists due to insufficient sanitization of user-supplied datawithin "NameVirtualHost". A remote user can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website.

Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.


Affected software

Twisted Web
Amazon Linux AMI
Gentoo Linux
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Enterprise Storage
SUSE OpenStack Cloud Crowbar
HPE Helion Openstack
SUSE OpenStack Cloud
Oracle Solaris
SUSE Linux Enterprise Module for Web Scripting
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Module for Server Applications
openSUSE Leap
openEuler
Ubuntu
SUSE Linux Enterprise Module for Packagehub Subpackages
python-twisted-web
python-Twisted
python-Twisted-debuginfo
python-Twisted-debugsource
python3-twisted (Ubuntu package)
python3-Twisted-debuginfo
python-Twisted-doc
python2-Twisted
python2-Twisted-debuginfo
python3-Twisted
python-twisted-help
python3-twisted
python-twisted
dev-python/twisted
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data

How to mitigate CVE-2022-39348

Install updates from vendor's website.

Twisted Web - update to 22.10.0 rc1
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.8.2
python-twisted-web - update to 8.2.0-6.8
python-Twisted - update to 15.2.1-9.23.1
python-Twisted-debuginfo - addressed in versions 15.2.1-9.23.1, 19.10.0-150200.3.18.1
python-Twisted-debugsource - addressed in versions 15.2.1-9.23.1, 19.10.0-150200.3.18.1
python3-twisted (Ubuntu package) - addressed in versions 18.9.0-11ubuntu0.20.04.3, 22.1.0-2ubuntu2.4, 22.4.0-4ubuntu0.23.04.1, 22.4.0-4ubuntu0.23.10.1
python3-Twisted-debuginfo - update to 19.10.0-150200.3.18.1
python-Twisted-doc - addressed in versions 19.10.0-150200.3.18.1, 22.2.0-150400.5.7.1
python2-Twisted - update to 19.10.0-150200.3.18.1
python2-Twisted-debuginfo - update to 19.10.0-150200.3.18.1
python3-Twisted - addressed in versions 19.10.0-150200.3.18.1, 22.2.0-150400.5.7.1
python-twisted-help - addressed in versions 22.4.0-1, 22.4.0-2
python3-twisted - addressed in versions 22.4.0-1, 22.4.0-2
python-twisted - addressed in versions 22.4.0-1, 22.4.0-2
python-twisted - update to 22.4.0-125
dev-python/twisted - update to 22.10.0

External References

Related Security Bulletins