You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
twisted is an event-driven networking engine written in Python. In affected versions twisted exposes cookies and authorization headers when following cross-origin redirects. This issue is present in the twited.web.RedirectAgent and twisted.web. BrowserLikeRedirectAgent functions. Users are advised to upgrade. There are no known workarounds.
CVE-2022-21712 - High Severity Vulnerability
An asynchronous networking framework written in Python
Library home page: https://files.pythonhosted.org/packages/4d/15/890ba1d83dc29ad71427ce5174d5963b84a25c8cf1973815107709fbb520/Twisted-20.3.0-cp27-cp27mu-manylinux1_x86_64.whl
Path to dependency file: /tmp/ws-scm/scrapy-pipelines
Path to vulnerable library: /tmp/ws-scm/scrapy-pipelines,/docs/requirements.txt,/requirements.txt
Dependency Hierarchy:
Found in base branch: master
twisted is an event-driven networking engine written in Python. In affected versions twisted exposes cookies and authorization headers when following cross-origin redirects. This issue is present in the
twited.web.RedirectAgent
andtwisted.web. BrowserLikeRedirectAgent
functions. Users are advised to upgrade. There are no known workarounds.Publish Date: 2022-02-07
URL: CVE-2022-21712
Base Score Metrics:
Type: Upgrade version
Origin: GHSA-92x2-jw7w-xvvx
Release Date: 2022-02-07
Fix Resolution: Twisted - 22.1.0
Step up your Open Source Security Game with Mend here
The text was updated successfully, but these errors were encountered: