Junglewise Threat Intelligence

CVE-2022-21712: PYSEC-2022-27 - twisted is an event-driven networking engine written in Python. In affected versions twisted exposes cookies and authorization headers when

CVE-2022-21712 · Severity: low · CVSS 3.1 · Published 2022-02-07

Technologies: twisted (PyPI). Vendors: PyPI.

Executive brief

twisted is an event-driven networking engine written in Python. In affected versions twisted exposes cookies and authorization headers when following cross-origin redirects. This issue is present in the `twited.web.RedirectAgent` and `twisted.web. BrowserLikeRedirectAgent` functions. Users are advised to upgrade. There are no known workarounds.

Affected products

  • PyPI twisted

Related threats