CVE-2022-21712: Cookie and header exposure in twisted
Impact
Cookie and Authorization headers are leaked when following cross-origin redirects in twited.web.client.RedirectAgent and twisted.web.client.BrowserLikeRedirectAgent.
Other sources
twisted is an event-driven networking engine written in Python. In affected versions twisted exposes cookies and authorization headers when following cross-origin redirects. This issue is present in the twited.web.RedirectAgent and twisted.web. BrowserLikeRedirectAgent functions. Users are advised to upgrade. There are no known workarounds.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2022-21712?
CVE-2022-21712 is a vulnerability in the Twisted library where cookies and authorization headers are exposed when following cross-origin redirects.
What is the severity of CVE-2022-21712?
The severity of CVE-2022-21712 is high with a CVSS score of 7.5.
How does CVE-2022-21712 affect Twisted?
CVE-2022-21712 affects Twisted versions between 11.1.0 and 22.1.0.
How does CVE-2022-21712 impact Debian Linux?
CVE-2022-21712 impacts Debian Linux version 9.0.
How do I fix CVE-2022-21712?
To fix CVE-2022-21712, update Twisted to version 22.1.0 or higher.