CVE-2019-12387: CRLF Injection
In Twisted before 19.2.1, twisted.web did not validate or sanitize URIs or HTTP methods, allowing an attacker to inject invalid characters such as CRLF.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2019-12387?
CVE-2019-12387 is a vulnerability in Twisted before 19.2.1 that allows an attacker to inject invalid characters such as CRLF into URIs or HTTP methods.
What is the severity of CVE-2019-12387?
The severity of CVE-2019-12387 is medium with a CVSS score of 6.1.
How does CVE-2019-12387 affect Twisted?
CVE-2019-12387 affects Twisted versions before 19.2.1.
How can I fix CVE-2019-12387?
To fix CVE-2019-12387, update Twisted to version 19.2.1 or higher.
Where can I find more information about CVE-2019-12387?
You can find more information about CVE-2019-12387 at the following references: [Reference 1](https://github.com/twisted/twisted/commit/6c61fc4503ae39ab8ecee52d10f10ee2c371d7e2), [Reference 2](https://labs.twistedmatrix.com/2019/06/twisted-1921-released.html), [Reference 3](https://twistedmatrix.com/pipermail/twisted-python/2019-June/032352.html).