Description
Twisted is an event-based framework for internet applications, supporting Python 3.6+. The `twisted.web.util.redirectTo` function contains an HTML injection vulnerability. If application code allows an attacker to control the redirect URL this vulnerability may result in Reflected Cross-Site Scripting (XSS) in the redirect response HTML body. This vulnerability is fixed in 24.7.0rc1.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-3970-1 | twisted security update |
Debian DSA |
DSA-5797-1 | twisted security update |
Github GHSA |
GHSA-cf56-g6w6-pqq2 | Twisted vulnerable to HTML injection in HTTP redirect body |
Ubuntu USN |
USN-6988-1 | Twisted vulnerabilities |
References
History
Mon, 03 Nov 2025 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Fri, 11 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Sat, 28 Sep 2024 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat
Redhat ansible Automation Platform |
|
| CPEs | cpe:/a:redhat:ansible_automation_platform:2.4::el8 cpe:/a:redhat:ansible_automation_platform:2.4::el9 |
|
| Vendors & Products |
Redhat
Redhat ansible Automation Platform |
Wed, 11 Sep 2024 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Twisted
Twisted twisted |
|
| CPEs | cpe:2.3:a:twisted:twisted:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Twisted
Twisted twisted |
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-11-03T22:01:01.094Z
Reserved: 2024-07-22T13:57:37.136Z
Link: CVE-2024-41810
Updated: 2024-08-02T04:46:52.679Z
Status : Modified
Published: 2024-07-29T16:15:05.133
Modified: 2025-11-03T22:17:34.527
Link: CVE-2024-41810
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA
Github GHSA
Ubuntu USN