Vulnerability Details CVE-2022-21712
twisted is an event-driven networking engine written in Python. In affected versions twisted exposes cookies and authorization headers when following cross-origin redirects. This issue is present in the `twited.web.RedirectAgent` and `twisted.web. BrowserLikeRedirectAgent` functions. Users are advised to upgrade. There are no known workarounds.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 43.5%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 5.0
Products affected by CVE-2022-21712
-
cpe:2.3:a:twisted:twisted:11.1.0
-
cpe:2.3:a:twisted:twisted:12.0.0
-
cpe:2.3:a:twisted:twisted:12.1.0
-
cpe:2.3:a:twisted:twisted:12.2.0
-
cpe:2.3:a:twisted:twisted:12.3.0
-
cpe:2.3:a:twisted:twisted:13.0.0
-
cpe:2.3:a:twisted:twisted:13.1.0
-
cpe:2.3:a:twisted:twisted:13.2.0
-
cpe:2.3:a:twisted:twisted:14.0.0
-
cpe:2.3:a:twisted:twisted:14.0.1
-
cpe:2.3:a:twisted:twisted:14.0.2
-
cpe:2.3:a:twisted:twisted:15.0.0
-
cpe:2.3:a:twisted:twisted:15.1.0
-
cpe:2.3:a:twisted:twisted:15.2.0
-
cpe:2.3:a:twisted:twisted:15.2.1
-
cpe:2.3:a:twisted:twisted:15.3.0
-
cpe:2.3:a:twisted:twisted:15.4.0
-
cpe:2.3:a:twisted:twisted:15.5.0
-
cpe:2.3:a:twisted:twisted:16.0.0
-
cpe:2.3:a:twisted:twisted:16.1.0
-
cpe:2.3:a:twisted:twisted:16.1.1
-
cpe:2.3:a:twisted:twisted:16.2.0
-
cpe:2.3:a:twisted:twisted:16.3.0
-
cpe:2.3:a:twisted:twisted:16.3.1
-
cpe:2.3:a:twisted:twisted:16.3.2
-
cpe:2.3:a:twisted:twisted:16.4.0
-
cpe:2.3:a:twisted:twisted:16.4.1
-
cpe:2.3:a:twisted:twisted:16.5.0
-
cpe:2.3:a:twisted:twisted:16.6.0
-
cpe:2.3:a:twisted:twisted:17.1.0
-
cpe:2.3:a:twisted:twisted:17.5.0
-
cpe:2.3:a:twisted:twisted:17.9.0
-
cpe:2.3:a:twisted:twisted:18.4.0
-
cpe:2.3:a:twisted:twisted:18.7.0
-
cpe:2.3:a:twisted:twisted:18.9.0
-
cpe:2.3:a:twisted:twisted:19.10.0
-
cpe:2.3:a:twisted:twisted:19.2.0
-
cpe:2.3:a:twisted:twisted:19.2.1
-
cpe:2.3:a:twisted:twisted:19.7.0
-
cpe:2.3:a:twisted:twisted:20.11.0
-
cpe:2.3:a:twisted:twisted:20.3.0
-
cpe:2.3:a:twisted:twisted:21.2.0
-
cpe:2.3:a:twisted:twisted:21.7.0
-
cpe:2.3:o:debian:debian_linux:9.0
-
cpe:2.3:o:fedoraproject:fedora:35
-
cpe:2.3:o:fedoraproject:fedora:36