ZeroHour

CVE-2019-12387

PoC ×2
CVSS 3.1
6.1 medium
EPSS
3%p84
Published
()
Modified
Description

In Twisted before 19.2.1, twisted.web did not validate or sanitize URIs or HTTP methods, allowing an attacker to inject invalid characters such as CRLF.

Vendors
twistedfedoraprojectcanonicaloracle
Products
twisted, fedora, ubuntu linux, zfs storage appliance kit, solaris
Weakness
CWE-74
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.