In Twisted Web through 19.10.0, there was an HTTP request splitting vulnerability. When presented with two content-length headers, it ignored the first header. When the second content-length value was set to zero, the request body was interpreted as a pipelined request.
References
Configurations
Information
Published : 2020-03-12 13:15
Updated : 2022-02-19 19:15
NVD link : CVE-2020-10108
Mitre link : CVE-2020-10108
JSON object : View
Products Affected
twistedmatrix
- twisted
CWE
CWE-20
Improper Input Validation
