Improper Access Control Affecting python-twisted-web package, versions <0:12.1.0-5.el7_2
Threat Intelligence
EPSS
0.05% (21st
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-RHEL7-PYTHONTWISTEDWEB-5364958
- published 27 Mar 2023
- disclosed 28 Aug 2017
Introduced: 28 Aug 2017
CVE-2017-10689 Open this link in a new tabHow to fix?
Upgrade RHEL:7 python-twisted-web to version 0:12.1.0-5.el7_2 or higher.
This issue was patched in RHSA-2018:2927.
NVD Description
Note: Versions mentioned in the description apply only to the upstream python-twisted-web package and not the python-twisted-web package as distributed by RHEL.
See How to fix? for RHEL:7 relevant fixed versions and status.
In previous versions of Puppet Agent it was possible to install a module with world writable permissions. Puppet Agent 5.3.4 and 1.10.10 included a fix to this vulnerability.