CVE-2022-39348

EUVD-2022-7164
Twisted is an event-based framework for internet applications. Started with version 0.9.4, when the host header does not match a configured host `twisted.web.vhost.NameVirtualHost` will return a `NoResource` resource which renders the Host header unescaped into the 404 response allowing HTML and script injection. In practice this should be very difficult to exploit as being able to modify the Host header of a normal HTTP request implies that one is already in a privileged position. This issue was fixed in version 22.10.0rc1. There are no known workarounds.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.4 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
GitHub_MCNA
5.4 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 78%
Affected Products (NVD)
VendorProductVersion
twistedtwisted
0.9.4 ≤
𝑥
< 22.10.0
debiandebian_linux
10.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
twisted
bookworm
22.4.0-4
fixed
bookworm (security)
22.4.0-4+deb12u1
fixed
bullseye
no-dsa
sid
24.10.0-1
fixed
trixie
24.7.0-3
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
twisted
bionic
needed
focal
Fixed 18.9.0-11ubuntu0.20.04.3
released
jammy
Fixed 22.1.0-2ubuntu2.4
released
kinetic
ignored
lunar
not-affected
mantic
not-affected
noble
not-affected
trusty
needed
xenial
needs-triage