CVE-2022-21712
â ī¸ highSummary
twisted is an event-driven networking engine written in Python. In affected versions twisted exposes cookies and authorization headers when following cross-origin redirects. This issue is present in the `twited.web.RedirectAgent` and `twisted.web. BrowserLikeRedirectAgent` functions. Users are advised to upgrade. There are no known workarounds.
CVSS Score
7.5
High
EPSS Score
0.2
Exploit Probability
Published Date
2022-02-07
First Seen: 2026-01-05
đ Relative Risk Intelligence
This CVE is Moderate Risk - more severe than 69.0% of all 328,009 vulnerabilities in our database.
#101,817
Above average severity
Severity Percentile
đ¯ CISA SSVC Assessment Updated: Apr 23, 2025
đ Exploitation Status
None
No known exploits
âī¸ Automatable
YES
Can be exploited automatically
đĨ Technical Impact
Partial
Limited system impact
SSVC data provided by
CISA
Last Modified
2024-11-25
Source
NVD đ
CVSS Vector 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N