Junglewise Threat Intelligence

CVE-2020-10108: PYSEC-2020-259 - In Twisted Web through 19.10.0, there was an HTTP request splitting vulnerability. When presented with two content-length headers, it ignore

CVE-2020-10108 · Severity: low · CVSS 3.1 · Published 2020-03-12

Technologies: twisted (PyPI). Vendors: PyPI.

Executive brief

In Twisted Web through 19.10.0, there was an HTTP request splitting vulnerability. When presented with two content-length headers, it ignored the first header. When the second content-length value was set to zero, the request body was interpreted as a pipelined request.

Affected products

  • PyPI twisted

Related threats