CVE-2024-41810

Twisted is an event-based framework for internet applications, supporting Python 3.6+. The `twisted.web.util.redirectTo` function contains an HTML injection vulnerability. If application code allows an attacker to control the redirect URL this vulnerability may result in Reflected Cross-Site Scripting (XSS) in the redirect response HTML body. This vulnerability is fixed in 24.7.0rc1.
Configurations

Configuration 1 (hide)

cpe:2.3:a:twisted:twisted:*:*:*:*:*:*:*:*

History

11 Sep 2024, 16:17

Type Values Removed Values Added
References () https://github.com/twisted/twisted/commit/046a164f89a0f08d3239ecebd750360f8914df33 - () https://github.com/twisted/twisted/commit/046a164f89a0f08d3239ecebd750360f8914df33 - Patch
References () https://github.com/twisted/twisted/security/advisories/GHSA-cf56-g6w6-pqq2 - () https://github.com/twisted/twisted/security/advisories/GHSA-cf56-g6w6-pqq2 - Vendor Advisory
CPE cpe:2.3:a:twisted:twisted:*:*:*:*:*:*:*:*
First Time Twisted
Twisted twisted
Summary
  • (es) Twisted es un framework basado en eventos para aplicaciones de Internet, compatible con Python 3.6+. La función `twisted.web.util.redirectTo` contiene una vulnerabilidad de inyección de HTML. Si el código de la aplicación permite a un atacante controlar la URL de redireccionamiento, esta vulnerabilidad puede provocar Cross Site Scripting reflejado (XSS) en el cuerpo HTML de la respuesta de redireccionamiento. Esta vulnerabilidad se soluciona en 24.7.0rc1.

29 Jul 2024, 16:21

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-29 16:15

Updated : 2024-09-11 16:17


NVD link : CVE-2024-41810

Mitre link : CVE-2024-41810

CVE.ORG link : CVE-2024-41810


JSON object : View

Products Affected

twisted

  • twisted
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CWE-80

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)