Forced Browsing in Twisted
Moderate severity
GitHub Reviewed
Published
Apr 30, 2021
to the GitHub Advisory Database
•
Updated Nov 18, 2024
Description
Published by the National Vulnerability Database
Mar 11, 2020
Reviewed
Apr 23, 2021
Published to the GitHub Advisory Database
Apr 30, 2021
Last updated
Nov 18, 2024
Twisted before 16.3.1 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI applications from the presence of untrusted client data in the
HTTP_PROXY
environment variable, which might allow remote attackers to redirect a CGI application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, aka anhttpoxy
issue.References