Open Redirect Affecting twisted package, versions [2.1.0,16.3.2]


Severity

Recommended
0.0
medium
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.27% (68th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Open Redirect vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-PYTHON-TWISTED-40368
  • published17 Jul 2016
  • disclosed17 Jul 2016
  • creditScott Geary

Introduced: 17 Jul 2016

CVE-2016-1000111  (opens in a new tab)
CWE-601  (opens in a new tab)

Overview

twisted is an asynchronous networking framework written in Python.

Affected versions of this package are is vulnerable to Open HTTP Redirects. It was discovered that python-twisted-web used the value of the Proxy header from HTTP requests to initialize the HTTP_PROXY environment variable for CGI scripts, which in turn was incorrectly used by certain HTTP client implementations to configure the proxy for outgoing HTTP requests. A remote attacker could possibly use this flaw to redirect HTTP requests performed by a CGI script to an attacker-controlled proxy via a malicious HTTP request.

CVSS Scores

version 3.1