Twisted Web HTTP Server Improper Neutralization of Special Elements in Output Used by a Downstream Component (Injection) Vulnerability - CVE-2019-12387 - Vulnerability Database
Twisted Web HTTP Server Improper Neutralization of Special Elements in Output Used by a Downstream Component (Injection) Vulnerability - CVE-2019-12387
Medium
Reference:
CVE-2019-12387
Title:
Twisted Web HTTP Server Improper Neutralization of Special Elements in Output Used by a Downstream Component (Injection) Vulnerability
Overview:
In Twisted before 19.2.1 twisted.web did not validate or sanitize URIs or HTTP methods allowing an attacker to inject invalid characters such as CRLF.