USN-6575-1

Source
https://ubuntu.com/security/notices/USN-6575-1
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-6575-1.json
JSON Data
https://api.osv.dev/v1/vulns/USN-6575-1
Upstream
Related
Published
2024-01-10T13:39:55.975325Z
Modified
2025-10-13T04:36:44Z
Summary
twisted vulnerabilities
Details

It was discovered that Twisted incorrectly escaped host headers in certain 404 responses. A remote attacker could possibly use this issue to perform HTML and script injection attacks. This issue only affected Ubuntu 20.04 LTS and Ubuntu 22.04 LTS. (CVE-2022-39348)

It was discovered that Twisted incorrectly handled response order when processing multiple HTTP requests. A remote attacker could possibly use this issue to delay responses and manipulate the responses of second requests. (CVE-2023-46137)

References

Affected packages

Ubuntu:20.04:LTS / twisted

Package

Name
twisted
Purl
pkg:deb/ubuntu/twisted@18.9.0-11ubuntu0.20.04.3?arch=source&distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
18.9.0-11ubuntu0.20.04.3

Affected versions

18.*

18.9.0-3ubuntu1
18.9.0-5
18.9.0-6
18.9.0-6build1
18.9.0-6ubuntu1
18.9.0-8
18.9.0-11
18.9.0-11ubuntu0.20.04.1
18.9.0-11ubuntu0.20.04.2

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_name": "python3-twisted",
            "binary_version": "18.9.0-11ubuntu0.20.04.3"
        },
        {
            "binary_name": "python3-twisted-bin",
            "binary_version": "18.9.0-11ubuntu0.20.04.3"
        }
    ]
}

Database specific

cves_map

{
    "ecosystem": "Ubuntu:20.04:LTS",
    "cves": [
        {
            "id": "CVE-2022-39348",
            "severity": [
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
                },
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
                },
                {
                    "type": "Ubuntu",
                    "score": "low"
                }
            ]
        },
        {
            "id": "CVE-2023-46137",
            "severity": [
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
                },
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
                },
                {
                    "type": "Ubuntu",
                    "score": "medium"
                }
            ]
        }
    ]
}

Ubuntu:22.04:LTS / twisted

Package

Name
twisted
Purl
pkg:deb/ubuntu/twisted@22.1.0-2ubuntu2.4?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
22.1.0-2ubuntu2.4

Affected versions

20.*

20.3.0-7ubuntu1
20.3.0-7ubuntu3

22.*

22.1.0-2ubuntu2
22.1.0-2ubuntu2.1
22.1.0-2ubuntu2.3

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_name": "python3-twisted",
            "binary_version": "22.1.0-2ubuntu2.4"
        }
    ]
}

Database specific

cves_map

{
    "ecosystem": "Ubuntu:22.04:LTS",
    "cves": [
        {
            "id": "CVE-2022-39348",
            "severity": [
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
                },
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
                },
                {
                    "type": "Ubuntu",
                    "score": "low"
                }
            ]
        },
        {
            "id": "CVE-2023-46137",
            "severity": [
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
                },
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
                },
                {
                    "type": "Ubuntu",
                    "score": "medium"
                }
            ]
        }
    ]
}