CVE-2022-24801
Twisted Web HTTP 1.1 Parsing Vulnerability
- CVSS 8.1
- CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
- Input Validation and Sanitization
- Remote
Twisted is an event-based framework for internet applications, supporting Python 3.6+. Prior to version 22.4.0rc1, the Twisted Web HTTP 1.1 server, located in the `twisted.web.http` module, parsed several HTTP request constructs more leniently than permitted by RFC 7230. This non-conformant parsing can lead to desync if requests pass through multiple HTTP parsers, potentially resulting in HTTP request smuggling. Users who may be affected use Twisted Web's HTTP 1.1 server and/or proxy and also pass requests through a different HTTP server and/or proxy. The Twisted Web client is not affected. The HTTP 2.0 server uses a different parser, so it is not affected. The issue has been addressed in Twisted 22.4.0rc1. Two workarounds are available: Ensure any vulnerabilities in upstream proxies have been addressed, such as by upgrading them; or filter malformed requests by other means, such as configuration of an upstream proxy.
- CVSS base score
- 8.1
- Published
- 2022-04-04
- OWASP
- A04 Insecure Design
- Orthogonal defect classification
- Function
- Code defect classification
- Incorrect Functionality
- Category
- Input Validation and Sanitization
- Subcategory
- Insecure Parsing or Deserialization
- Accessibility scope
- Remote
- Impact
- Denial of Service (DoS)
- Fixed by upgrading
- Yes
Solution
Update to Twisted 22.4.0rc1 or higher.
Vulnerable code sample
from twisted.web import server, resource
from twisted.internet import reactor
class VulnerableResource(resource.Resource):
isLeaf = True
def render_GET(self, request):
# VULNERABLE: This code is susceptible to xss
# This method is intentionally lenient in parsing
# HTTP requests, which can lead to vulnerabilities.
return b"Vulnerable Response"
# Create a Twisted HTTP server with the vulnerable resource
site = server.Site(VulnerableResource())
reactor.listenTCP(8080, site)
reactor.run()Patched code sample
from twisted.web import server, resource
from twisted.internet import reactor
class Simple(resource.Resource):
isLeaf = True
def render_GET(self, request):
# SECURE: This version prevents xss
return b"Hello, World!"
# Create a Twisted HTTP server
site = server.Site(Simple())
reactor.listenTCP(8080, site)
reactor.run()Cite this entry
@misc{vaitp:cve202224801,
title = {{Twisted Web HTTP 1.1 Parsing Vulnerability}},
author = {Bogaerts, Fr\'ed\'eric and Ivaki, Naghmeh and Fonseca, Jos\'e},
year = {2022},
note = {VAITP Python Vulnerability Dataset, entry CVE-2022-24801},
howpublished = {\url{https://netpack.pt/vaitp/vulnerability/CVE-2022-24801/}}
}
Introducing the "VAITP dataset": a specialized repository of Python vulnerabilities and patches, meticulously compiled for the use of the security research community. As Python's prominence grows, understanding and addressing potential security vulnerabilities become crucial. Crafted by and for the cybersecurity community, this dataset offers a valuable resource for researchers, analysts, and developers to analyze and mitigate the security risks associated with Python. Through the comprehensive exploration of vulnerabilities and corresponding patches, the VAITP dataset fosters a safer and more resilient Python ecosystem, encouraging collaborative advancements in programming security.
The supreme art of war is to subdue the enemy without fighting.
Sun Tzu – “The Art of War”
:: Shaping the future through research and ingenuity ::
