In Twisted Web through 19.10.0, there was an HTTP request splitting vulnerability. When presented with a content-length and a chunked encoding header, the content-length took precedence and the remainder of the request body was interpreted as a pipelined request.
References
Configurations
Information
Published : 2020-03-12 13:15
Updated : 2022-02-19 19:15
NVD link : CVE-2020-10109
Mitre link : CVE-2020-10109
JSON object : View
Products Affected
twistedmatrix
- twisted
CWE
CWE-444
Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
