CVE-2022-21712 (https://github.com/twisted/twisted/security/advisories/GHSA-92x2-jw7w-xvvx): twisted is an event-driven networking engine written in Python. In affected versions twisted exposes cookies and authorization headers when following cross-origin redirects. This issue is present in the `twited.web.RedirectAgent` and `twisted.web. BrowserLikeRedirectAgent` functions. Users are advised to upgrade. There are no known workarounds. Please bump to >22.1.
> Please bump to >22.1. Easy for you to say :-P.
Thanks!
Cleanup done.
GLSA request filed
The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/data/glsa.git/commit/?id=2bcf5e2e8d41a687f63bb2d3acc767b943e61b24 commit 2bcf5e2e8d41a687f63bb2d3acc767b943e61b24 Author: GLSAMaker <glsamaker@gentoo.org> AuthorDate: 2023-01-11 05:16:16 +0000 Commit: John Helmert III <ajak@gentoo.org> CommitDate: 2023-01-11 05:22:04 +0000 [ GLSA 202301-02 ] Twisted: Multiple Vulnerabilities Bug: https://bugs.gentoo.org/832875 Bug: https://bugs.gentoo.org/834542 Bug: https://bugs.gentoo.org/878499 Signed-off-by: GLSAMaker <glsamaker@gentoo.org> Signed-off-by: John Helmert III <ajak@gentoo.org> glsa-202301-02.xml | 46 ++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 46 insertions(+)
GLSA released, all done!