CVE-2019-12387 PUBLISHED

In Twisted before 19.2.1, twisted.web did not validate or sanitize URIs or HTTP methods, allowing an attacker to inject invalid characters such as CRLF.

EPSS 0.53% · 67.1th percentile

Risk Scores

EPSS Score
0.53%
67.1th percentile

Affected Products

VendorProductVersions
Ubuntu:18.04:LTStwisted17.9.0-2, 17.9.0-1, 16.6.0-2ubuntu3
Ubuntu:Pro:14.04:LTStwisted0, 13.0.0-1ubuntu1, 13.2.0-1ubuntu1
Ubuntu:16.04:LTStwisted15.5.0-2ubuntu1, 15.5.0-4, 16.0.0~pre1-1

Timeline

References

Open in Interactive Console →