Advisories ยป MGASA-2023-0061

Updated python-twisted packages fix security vulnerability

Publication date: 27 Feb 2023
Modification date: 27 Feb 2023
Type: security
Affected Mageia releases : 8
CVE: CVE-2022-39348

Description

When the host header does not match a configured host
twisted.web.vhost.NameVirtualHost will return a NoResource resource which
renders the Host header unescaped into the 404 response allowing HTML and
script injection. (CVE-2022-39348)
                

References

SRPMS

8/core