VAITP Dataset

← Back to the dataset

CVE-2022-24801

Twisted Web HTTP 1.1 Parsing Vulnerability

  • CVSS 8.1
  • CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
  • Input Validation and Sanitization
  • Remote

Twisted is an event-based framework for internet applications, supporting Python 3.6+. Prior to version 22.4.0rc1, the Twisted Web HTTP 1.1 server, located in the `twisted.web.http` module, parsed several HTTP request constructs more leniently than permitted by RFC 7230. This non-conformant parsing can lead to desync if requests pass through multiple HTTP parsers, potentially resulting in HTTP request smuggling. Users who may be affected use Twisted Web's HTTP 1.1 server and/or proxy and also pass requests through a different HTTP server and/or proxy. The Twisted Web client is not affected. The HTTP 2.0 server uses a different parser, so it is not affected. The issue has been addressed in Twisted 22.4.0rc1. Two workarounds are available: Ensure any vulnerabilities in upstream proxies have been addressed, such as by upgrading them; or filter malformed requests by other means, such as configuration of an upstream proxy.

CVSS base score
8.1
Published
2022-04-04
OWASP
A04 Insecure Design
Orthogonal defect classification
Function
Code defect classification
Incorrect Functionality
Category
Input Validation and Sanitization
Subcategory
Insecure Parsing or Deserialization
Accessibility scope
Remote
Impact
Denial of Service (DoS)
Fixed by upgrading
Yes

Solution

Update to Twisted 22.4.0rc1 or higher.

Vulnerable code sample

from twisted.web import server, resource
from twisted.internet import reactor

class VulnerableResource(resource.Resource):
    isLeaf = True

    def render_GET(self, request):
    # VULNERABLE: This code is susceptible to xss
        # This method is intentionally lenient in parsing
        # HTTP requests, which can lead to vulnerabilities.
        return b"Vulnerable Response"

# Create a Twisted HTTP server with the vulnerable resource
site = server.Site(VulnerableResource())
reactor.listenTCP(8080, site)
reactor.run()

Patched code sample

from twisted.web import server, resource
from twisted.internet import reactor

class Simple(resource.Resource):
    isLeaf = True

    def render_GET(self, request):
    # SECURE: This version prevents xss
        return b"Hello, World!"

# Create a Twisted HTTP server
site = server.Site(Simple())
reactor.listenTCP(8080, site)
reactor.run()

Cite this entry

@misc{vaitp:cve202224801,
  title        = {{Twisted Web HTTP 1.1 Parsing Vulnerability}},
  author       = {Bogaerts, Fr\'ed\'eric and Ivaki, Naghmeh and Fonseca, Jos\'e},
  year         = {2022},
  note         = {VAITP Python Vulnerability Dataset, entry CVE-2022-24801},
  howpublished = {\url{https://netpack.pt/vaitp/vulnerability/CVE-2022-24801/}}
}
Introducing the "VAITP dataset": a specialized repository of Python vulnerabilities and patches, meticulously compiled for the use of the security research community. As Python's prominence grows, understanding and addressing potential security vulnerabilities become crucial. Crafted by and for the cybersecurity community, this dataset offers a valuable resource for researchers, analysts, and developers to analyze and mitigate the security risks associated with Python. Through the comprehensive exploration of vulnerabilities and corresponding patches, the VAITP dataset fosters a safer and more resilient Python ecosystem, encouraging collaborative advancements in programming security.

The supreme art of war is to subdue the enemy without fighting.

Sun Tzu – “The Art of War”

:: Shaping the future through research and ingenuity ::