CVE-2022-24801 (CNNVD-202204-1931)
中文标题:
Twisted 环境问题漏洞
英文标题:
HTTP Request Smuggling in twisted.web
漏洞描述
中文描述:
Twisted是一款使用Python语言编写的事件驱动的开源网络引擎。 Twisted 存在环境问题漏洞,该漏洞源于在版本22.4.0rc1之前,Twisted Web HTTP 1.1服务器位于Twisted中。网状物http模块,比RFC 7230允许的更轻松地解析了几个http请求构造。如果请求通过多个HTTP解析器,这种不一致的解析可能会导致去同步,从而可能导致HTTP请求走私。
英文描述:
Twisted is an event-based framework for internet applications, supporting Python 3.6+. Prior to version 22.4.0rc1, the Twisted Web HTTP 1.1 server, located in the `twisted.web.http` module, parsed several HTTP request constructs more leniently than permitted by RFC 7230. This non-conformant parsing can lead to desync if requests pass through multiple HTTP parsers, potentially resulting in HTTP request smuggling. Users who may be affected use Twisted Web's HTTP 1.1 server and/or proxy and also pass requests through a different HTTP server and/or proxy. The Twisted Web client is not affected. The HTTP 2.0 server uses a different parser, so it is not affected. The issue has been addressed in Twisted 22.4.0rc1. Two workarounds are available: Ensure any vulnerabilities in upstream proxies have been addressed, such as by upgrading them; or filter malformed requests by other means, such as configuration of an upstream proxy.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| twisted | twisted | <= 22.2.0 | - | - |
cpe:2.3:a:twisted:twisted:<=_22.2.0:*:*:*:*:*:*:*
|
| twisted | twisted | * | - | - |
cpe:2.3:a:twisted:twisted:*:*:*:*:*:*:*:*
|
| debian | debian_linux | 9.0 | - | - |
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
|
| fedoraproject | fedora | 35 | - | - |
cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*
|
| fedoraproject | fedora | 36 | - | - |
cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*
|
| oracle | zfs_storage_appliance_kit | 8.8 | - | - |
cpe:2.3:a:oracle:zfs_storage_appliance_kit:8.8:*:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
参考链接
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
CVSS评分详情
3.1 (cna)
HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2022-24801 |
2025-11-11 15:21:19 | 2025-11-11 07:37:22 |
| NVD | nvd_CVE-2022-24801 |
2025-11-11 14:58:16 | 2025-11-11 07:45:38 |
| CNNVD | cnnvd_CNNVD-202204-1931 |
2025-11-11 15:10:51 | 2025-11-11 07:57:13 |
版本与语言
安全公告
变更历史
查看详细变更
- vulnerability_type: 未提取 -> 环境问题
- cnnvd_id: 未提取 -> CNNVD-202204-1931
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- affected_products_count: 1 -> 6
- data_sources: ['cve'] -> ['cve', 'nvd']