Inconsistent interpretation of HTTP requests in Twisted Web - CVE-2023-46137

 

Inconsistent interpretation of HTTP requests in Twisted Web - CVE-2023-46137

Published: October 30, 2023


Vulnerability identifier: #VU82547
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-46137
CWE-ID: CWE-444
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform HTTP request smuggling attacks.

The vulnerability exists due to improper validation of HTTP requests. A remote attacker can send a specially crafted HTTP request to the server and smuggle arbitrary HTTP headers.

Successful exploitation of vulnerability may allow an attacker to poison HTTP cache and perform phishing attacks.


Affected software

Twisted Web
Amazon Linux AMI
Debian Linux
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Manager Proxy
Public Cloud Module
Server Applications Module
Python 3 Module
openSUSE Leap
openEuler
Ubuntu
Ansible Automation Platform
Red Hat OpenStack for IBM Power
Red Hat OpenStack
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
Red Hat OpenStack Director Deployment Tools
receptor (Red Hat package)
ansible-runner (Red Hat package)
ansible-core (Red Hat package)
python3x-dynaconf (Red Hat package)
python-dynaconf (Red Hat package)
python3x-gitpython (Red Hat package)
python-gitpython (Red Hat package)
python3x-aiohttp (Red Hat package)
python-aiohttp (Red Hat package)
python3x-pulpcore (Red Hat package)
python-pulpcore (Red Hat package)
python3x-django (Red Hat package)
python-django (Red Hat package)
automation-controller (Red Hat package)
python-twisted (Red Hat package)
python3-Twisted
python3-twisted (Ubuntu package)
python-Twisted-debuginfo
python-Twisted-debugsource
python-Twisted-doc
python3-twisted
python-twisted-help
python-twisted
twisted (Debian package)
python311-Twisted-all_non_platform
python311-Twisted-conch
python311-Twisted-http2
python311-Twisted-contextvars
python311-Twisted-tls
python311-Twisted-serial
python311-Twisted-conch_nacl
python311-Twisted
python3x-twisted (Red Hat package)

How to mitigate CVE-2023-46137

Install updates from vendor's website.

Twisted Web - addressed in versions 23.8.0, 23.10.0 rc1
receptor (Red Hat package) - addressed in versions 1.4.5-1.el8ap, 1.4.5-1.el9ap
ansible-runner (Red Hat package) - addressed in versions 2.3.6-1.el8ap, 2.3.6-1.el9ap
ansible-core (Red Hat package) - addressed in versions 2.15.10-1.el8ap, 2.15.10-1.el9ap
python3x-dynaconf (Red Hat package) - update to 3.1.12-2.el8ap
python-dynaconf (Red Hat package) - update to 3.1.12-2.el9ap
python3x-gitpython (Red Hat package) - update to 3.1.40-1.el8ap
python-gitpython (Red Hat package) - update to 3.1.40-1.el9ap
python3x-aiohttp (Red Hat package) - update to 3.9.3-1.el8ap
python-aiohttp (Red Hat package) - update to 3.9.3-1.el9ap
python3x-pulpcore (Red Hat package) - update to 3.28.24-1.el8ap
python-pulpcore (Red Hat package) - update to 3.28.24-1.el9ap
python3x-django (Red Hat package) - update to 4.2.11-1.el8ap
python-django (Red Hat package) - update to 4.2.11-1.el9ap
automation-controller (Red Hat package) - addressed in versions 4.5.5-2.el8ap, 4.5.5-2.el9ap
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.8.2
python-twisted (Red Hat package) - addressed in versions 16.4.1-21.el8ost, 23.10.0-1.el9ap
python3-Twisted - addressed in versions 17.9.0-150000.3.11.1, 22.2.0-150400.15.1
python3-twisted (Ubuntu package) - addressed in versions 18.9.0-11ubuntu0.20.04.3, 22.1.0-2ubuntu2.4, 22.4.0-4ubuntu0.23.04.1, 22.4.0-4ubuntu0.23.10.1
python-Twisted-debuginfo - update to 19.10.0-150200.3.21.1
python-Twisted-debugsource - update to 19.10.0-150200.3.21.1
python-Twisted-doc - update to 22.2.0-150400.15.1
python3-twisted - addressed in versions 22.4.0-2, 22.4.0-3
python-twisted-help - addressed in versions 22.4.0-2, 22.4.0-3
python-twisted - addressed in versions 22.4.0-2, 22.4.0-3
twisted (Debian package) - update to 22.4.0-4+deb12u1
python-twisted - update to 22.4.0-126
python311-Twisted-all_non_platform - update to 22.10.0-150400.5.13.1
python311-Twisted-conch - update to 22.10.0-150400.5.13.1
python311-Twisted-http2 - update to 22.10.0-150400.5.13.1
python311-Twisted-contextvars - update to 22.10.0-150400.5.13.1
python311-Twisted-tls - update to 22.10.0-150400.5.13.1
python311-Twisted-serial - update to 22.10.0-150400.5.13.1
python311-Twisted-conch_nacl - update to 22.10.0-150400.5.13.1
python311-Twisted - update to 22.10.0-150400.5.13.1
python3x-twisted (Red Hat package) - update to 23.10.0-1.el8ap

External References

Related Security Bulletins