First published: Mon Feb 07 2022(Updated: )
### Impact Cookie and Authorization headers are leaked when following cross-origin redirects in `twited.web.client.RedirectAgent` and `twisted.web.client.BrowserLikeRedirectAgent`.
Credit: security-advisories@github.com security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
Twistedmatrix Twisted | >=11.1.0<22.1.0 | |
Debian Debian Linux | =9.0 | |
Fedoraproject Fedora | =35 | |
Fedoraproject Fedora | =36 | |
pip/Twisted | >=11.1.0<22.1.0 | 22.1.0 |
Twisted Twisted | >=11.1.0<22.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-21712 is a vulnerability in the Twisted library where cookies and authorization headers are exposed when following cross-origin redirects.
The severity of CVE-2022-21712 is high with a CVSS score of 7.5.
CVE-2022-21712 affects Twisted versions between 11.1.0 and 22.1.0.
CVE-2022-21712 impacts Debian Linux version 9.0.
To fix CVE-2022-21712, update Twisted to version 22.1.0 or higher.