VDB
ALINUX2-SA-2020%3A0043
ALINUX2-SA-2020%3A0043
PUBLISHED
CVSS 6.5 MEDIUM
Package updates are available for Alibaba Cloud Linux 2.1903 that fix the following vulnerabilities: CVE-2019-12387: In Twisted before 19.2.1, twisted.web did not validate or sanitize URIs or HTTP methods, allowing an attacker to inject invalid characters such as CRLF.
Risk Scores
CVSS 3.0
6.5
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Alibaba Cloud | python-twisted-web |
Timeline
- Apr 2, 2020 CVE Published
- Apr 2, 2020 CVE Updated