Show filters
15 Total Results
Displaying 11-15 of 15
Sort by:
Attacker Value
Unknown
CVE-2016-1000111
Disclosure Date: March 11, 2020 (last updated February 21, 2025)
Twisted before 16.3.1 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect a CGI application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, aka an "httpoxy" issue.
0
Attacker Value
Unknown
CVE-2014-7143
Disclosure Date: November 12, 2019 (last updated November 28, 2024)
Python Twisted 14.0 trustRoot is not respected in HTTP client
0
Attacker Value
Unknown
CVE-2019-12855
Disclosure Date: June 16, 2019 (last updated November 28, 2024)
In words.protocols.jabber.xmlstream in Twisted through 19.2.1, XMPP support did not verify certificates when used with TLS, allowing an attacker to MITM connections.
0
Attacker Value
Unknown
CVE-2019-12387
Disclosure Date: June 10, 2019 (last updated November 28, 2024)
In Twisted before 19.2.1, twisted.web did not validate or sanitize URIs or HTTP methods, allowing an attacker to inject invalid characters such as CRLF.
0
Attacker Value
Unknown
CVE-2017-1000007
Disclosure Date: July 17, 2017 (last updated November 26, 2024)
txAWS (all current versions) fail to perform complete certificate verification resulting in vulnerability to MitM attacks and information disclosure.
0