Lucene search

K
osvGoogleOSV:USN-5354-1
HistoryMar 30, 2022 - 8:17 a.m.

twisted vulnerabilities

2022-03-3008:17:48
Google
osv.dev
11
twisted
software
vulnerabilities
http
headers
ssh
handshake
processing
remote attacker
sensitive information
denial of service
cve-2022-21712
cve-2022-21716

AI Score

6.8

Confidence

Low

EPSS

0.004

Percentile

74.8%

It was discovered that Twisted incorrectly filtered HTTP headers when clients
are being redirected to another origin. A remote attacker could use this issue
to obtain sensitive information. (CVE-2022-21712)

It was discovered that Twisted incorrectly processed SSH handshake data on
connection establishments. A remote attacker could use this issue to cause
Twisted to crash, resulting in a denial of service. (CVE-2022-21716)