CVE-2022-21712
twisted is an event-driven networking engine written in Python. In affected versions twisted exposes cookies and authori
twisted is an event-driven networking engine written in Python. In affected versions twisted exposes cookies and authorization headers when following cross-origin redirects. This issue is present in the twited.web.RedirectAgent and `twisted.web.
BrowserLikeRedirectAgent` functions. Users are advised to upgrade. There are no known workarounds.
HIGH · CVSS 7.5
EPSS 0.00241
Schedule remediation
- SSVC automatable: yes - attacks can be scripted at scale
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0