VDB
BDU%3A2024-06573
BDU%3A2024-06573
PUBLISHED
CVSS 8.300000190734863 HIGH
Уязвимость компонента twisted.web сетевого фреймворка Twisted, позволяющая нарушителю раскрыть защищаемую информацию
Risk Scores
CVSS 3.1
8.300000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| twisted | twisted | 0 |
| twisted | twisted | <= 24.3.0 |
| Сообщество свободного программного обеспечения, ООО «Ред Софт», ООО «РусБИТех-Астра», Glyph Lefkowitz, АО "НППКТ" | Debian GNU/Linux, РЕД ОС (запись в едином реестре российских программ №3751), Astra Linux Special Edition (запись в едином реестре российских программ №369), Twisted, ОСОН ОСнова Оnyx (запись в едином реестре российских программ №5913) |
Timeline
- Jul 29, 2024 PoC Published
- Jul 29, 2024 CVE Published
- Jul 29, 2024 PoC Published
- Sep 23, 2025 CVE Updated
References
- https://security-tracker.debian.org/tracker/CVE-2024-41671 url
- https://vuldb.com/ru/?id.272715 url
- https://github.com/twisted/twisted/security/advisories/GHSA-c8m8-j448-xjx7 url
- https://vulners.com/nvd/NVD:CVE-2024-41671 url
- https://поддержка.нппкт.рф/bin/view/ОСнова/Обновления/2.12/ url
- https://wiki.astralinux.ru/astra-linux-se17-bulletin-2025-0319SE17 url
- https://wiki.astralinux.ru/astra-linux-se47-bulletin-2025-0422SE47 url
- http://repo.red-soft.ru/redos/7.3c/x86_64/updates/ url
- https://github.com/twisted/twisted/commit/046a164f89a0f08d3239ecebd750360f8914df33 advisory
- https://github.com/twisted/twisted/commit/4a930de12fb67e88fefcb8822104152f42b27abc advisory
- https://www.vicarius.io/vsociety/posts/disordered-http-pipeline-in-twistedweb-cve-2024-4167 url
- https://lists.debian.org/debian-lts-announce/2024/11/msg00028.html url