{"schema_version":"1.7.3","id":"GHSA-h96w-mmrf-2h6v","published":"2020-03-31T15:42:42Z","modified":"2024-11-25T18:48:08.662171Z","aliases":["CVE-2020-10108","PYSEC-2020-259"],"summary":"Improper Input Validation in Twisted","details":"In Twisted Web before 20.3.0, there was an HTTP request splitting vulnerability. When presented with two content-length headers, it ignored the first header. When the second content-length value was set to zero, the request body was interpreted as a pipelined request.","affected":[{"package":{"name":"twisted","ecosystem":"PyPI","purl":"pkg:pypi/twisted"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"20.3.0"}]}],"versions":["1.0.1","1.0.3","1.0.4","1.0.5","1.0.6","1.0.7","1.1.0","1.1.1","1.2.0","10.0.0","10.1.0","10.2.0","11.0.0","11.1.0","12.0.0","12.1.0","12.2.0","12.3.0","13.0.0","13.1.0","13.2.0","14.0.0","14.0.1","14.0.2","15.0.0","15.1.0","15.2.0","15.2.1","15.3.0","15.4.0","15.5.0","16.0.0","16.1.0","16.1.1","16.2.0","16.3.0","16.3.1","16.3.2","16.4.0","16.4.1","16.5.0","16.5.0rc1","16.5.0rc2","16.6.0","16.6.0rc1","16.7.0rc1","16.7.0rc2","17.1.0","17.1.0rc1","17.5.0","17.9.0","17.9.0rc1","18.4.0","18.4.0rc1","18.7.0","18.7.0rc1","18.7.0rc2","18.9.0","18.9.0rc1","19.10.0","19.10.0rc1","19.2.0","19.2.0rc1","19.2.0rc2","19.2.1","19.7.0","19.7.0rc1","2.1.0","2.4.0","2.5.0","20.3.0rc1","8.0.0","8.0.1","8.1.0","8.2.0","9.0.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/03/GHSA-h96w-mmrf-2h6v/GHSA-h96w-mmrf-2h6v.json"}}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-10108"},{"type":"WEB","url":"https://github.com/twisted/twisted/commit/4a7d22e490bb8ff836892cc99a1f54b85ccb0281"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/twisted/PYSEC-2020-259.yaml"},{"type":"PACKAGE","url":"https://github.com/twisted/twisted"},{"type":"WEB","url":"https://github.com/twisted/twisted/blob/6ff2c40e42416c83203422ff70dfc49d2681c8e2/NEWS.rst#twisted-2030-2020-03-13"},{"type":"WEB","url":"https://know.bishopfox.com/advisories"},{"type":"WEB","url":"https://know.bishopfox.com/advisories/twisted-version-19.10.0"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2022/02/msg00021.html"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6ISMZFZBWW4EV6ETJGXAYIXN3AT7GBPL"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YW3NIL7VXSGJND2Q4BSXM3CFTAFU6T7D"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6ISMZFZBWW4EV6ETJGXAYIXN3AT7GBPL"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YW3NIL7VXSGJND2Q4BSXM3CFTAFU6T7D"},{"type":"WEB","url":"https://security.gentoo.org/glsa/202007-24"},{"type":"WEB","url":"https://usn.ubuntu.com/4308-1"},{"type":"WEB","url":"https://usn.ubuntu.com/4308-2"},{"type":"WEB","url":"https://www.oracle.com/security-alerts/cpuoct2020.html"}],"database_specific":{"cwe_ids":["CWE-20","CWE-444"],"github_reviewed":true,"github_reviewed_at":"2020-03-31T15:28:25Z","nvd_published_at":"2020-03-12T13:15:00Z","severity":"CRITICAL"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}]}