Search CVE reports
1 – 4 of 4 results
Some fixes available 4 of 6
In words.protocols.jabber.xmlstream in Twisted through 19.2.1, XMPP support did not verify certificates when used with TLS, allowing an attacker to MITM connections.
2 affected packages
twisted, twisted-py3
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
twisted | — | — | — | Fixed |
twisted-py3 | — | — | — | Not in release |
Some fixes available 4 of 6
In Twisted before 19.2.1, twisted.web did not validate or sanitize URIs or HTTP methods, allowing an attacker to inject invalid characters such as CRLF.
2 affected packages
twisted, twisted-py3
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
twisted | — | — | — | Fixed |
twisted-py3 | — | — | — | Not in release |
Some fixes available 2 of 7
Twisted before 16.3.1 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which...
2 affected packages
twisted, twisted-py3
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
twisted | — | — | — | Not affected |
twisted-py3 | — | — | — | Not in release |
Python Twisted 14.0 trustRoot is not respected in HTTP client
2 affected packages
twisted, twisted-py3
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
twisted | — | — | — | — |
twisted-py3 | — | — | — | — |