Vulnerability Details CVE-2020-10108
In Twisted Web through 19.10.0, there was an HTTP request splitting vulnerability. When presented with two content-length headers, it ignored the first header. When the second content-length value was set to zero, the request body was interpreted as a pipelined request.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.051
EPSS Ranking 89.4%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 7.5
Products affected by CVE-2020-10108
-
cpe:2.3:a:oracle:zfs_storage_appliance_kit:8.8
-
cpe:2.3:a:twisted:twisted:-
-
cpe:2.3:a:twisted:twisted:10.0.0
-
cpe:2.3:a:twisted:twisted:10.1.0
-
cpe:2.3:a:twisted:twisted:10.2.0
-
cpe:2.3:a:twisted:twisted:11.0.0
-
cpe:2.3:a:twisted:twisted:11.1.0
-
cpe:2.3:a:twisted:twisted:12.0.0
-
cpe:2.3:a:twisted:twisted:12.1.0
-
cpe:2.3:a:twisted:twisted:12.2.0
-
cpe:2.3:a:twisted:twisted:12.3.0
-
cpe:2.3:a:twisted:twisted:13.0.0
-
cpe:2.3:a:twisted:twisted:13.1.0
-
cpe:2.3:a:twisted:twisted:13.2.0
-
cpe:2.3:a:twisted:twisted:14.0.0
-
cpe:2.3:a:twisted:twisted:14.0.1
-
cpe:2.3:a:twisted:twisted:14.0.2
-
cpe:2.3:a:twisted:twisted:15.0.0
-
cpe:2.3:a:twisted:twisted:15.1.0
-
cpe:2.3:a:twisted:twisted:15.2.0
-
cpe:2.3:a:twisted:twisted:15.2.1
-
cpe:2.3:a:twisted:twisted:15.3.0
-
cpe:2.3:a:twisted:twisted:15.4.0
-
cpe:2.3:a:twisted:twisted:15.5.0
-
cpe:2.3:a:twisted:twisted:16.0.0
-
cpe:2.3:a:twisted:twisted:16.1.0
-
cpe:2.3:a:twisted:twisted:16.1.1
-
cpe:2.3:a:twisted:twisted:16.2.0
-
cpe:2.3:a:twisted:twisted:16.3.0
-
cpe:2.3:a:twisted:twisted:16.3.1
-
cpe:2.3:a:twisted:twisted:16.3.2
-
cpe:2.3:a:twisted:twisted:16.4.0
-
cpe:2.3:a:twisted:twisted:16.4.1
-
cpe:2.3:a:twisted:twisted:16.5.0
-
cpe:2.3:a:twisted:twisted:16.6.0
-
cpe:2.3:a:twisted:twisted:17.1.0
-
cpe:2.3:a:twisted:twisted:17.5.0
-
cpe:2.3:a:twisted:twisted:17.9.0
-
cpe:2.3:a:twisted:twisted:18.4.0
-
cpe:2.3:a:twisted:twisted:18.7.0
-
cpe:2.3:a:twisted:twisted:18.9.0
-
cpe:2.3:a:twisted:twisted:19.10.0
-
cpe:2.3:a:twisted:twisted:19.2.0
-
cpe:2.3:a:twisted:twisted:19.2.1
-
cpe:2.3:a:twisted:twisted:19.7.0
-
cpe:2.3:a:twisted:twisted:8.0.0
-
cpe:2.3:a:twisted:twisted:8.0.1
-
cpe:2.3:a:twisted:twisted:8.1.0
-
cpe:2.3:a:twisted:twisted:8.2.0
-
cpe:2.3:a:twisted:twisted:9.0.0
-
cpe:2.3:o:canonical:ubuntu_linux:14.04
-
cpe:2.3:o:canonical:ubuntu_linux:16.04
-
cpe:2.3:o:canonical:ubuntu_linux:18.04
-
cpe:2.3:o:canonical:ubuntu_linux:19.10
-
cpe:2.3:o:debian:debian_linux:9.0
-
cpe:2.3:o:fedoraproject:fedora:31
-
cpe:2.3:o:fedoraproject:fedora:32
-
cpe:2.3:o:oracle:solaris:10
-
cpe:2.3:o:oracle:solaris:11