Amazon Linux 2 Security Advisory: ALAS-2022-1827
Advisory Release Date: 2022-07-19 01:22 Pacific
Advisory Updated Date: 2022-07-20 22:25 Pacific
A flaw was found in python-twisted. This vulnerability occurs due to the parsing of illegal constructs in the twisted.web.http module. The illegal constructs include '+/-' in the Content-Length header, '\n and \t' etc. Non-conformant parsing leads to a desync if requests pass through multiple HTTP parsers. This flaw allows a remote attacker to perform an HTTP request smuggling attack. (CVE-2022-24801)
Affected Packages:
python-twisted-web
Note:
This advisory is applicable to Amazon Linux 2 (AL2) Core repository. Visit this FAQ section for the difference between AL2 Core and AL2 Extras advisories.
Issue Correction:
Run yum update python-twisted-web to update your system.
aarch64:
python-twisted-web-12.1.0-8.amzn2.aarch64
i686:
python-twisted-web-12.1.0-8.amzn2.i686
src:
python-twisted-web-12.1.0-8.amzn2.src
x86_64:
python-twisted-web-12.1.0-8.amzn2.x86_64