ELA-566-1 twisted security update

information leak

2022-02-19
Packagetwisted
Version14.0.2-3+deb8u3
Related CVEs CVE-2022-21712


It was discovered that Twisted, a Python event-based framework for internet applications, exposes cookies and authorization headers when following cross-origin redirects. This issue is present in the twisted.web.RedirectAgent and twisted.web.BrowserLikeRedirectAgent functions.



For Debian 8 jessie, these problems have been fixed in version 14.0.2-3+deb8u3.

We recommend that you upgrade your twisted packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.