VDB
KO

PYSEC-2022-27

Details

twisted is an event-driven networking engine written in Python. In affected versions twisted exposes cookies and authorization headers when following cross-origin redirects. This issue is present in the `twited.web.RedirectAgent` and `twisted.web. BrowserLikeRedirectAgent` functions. Users are advised to upgrade. There are no known workarounds.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI / twisted
Introduced in: 0 Fixed in: af8fe78542a6f2bf2235ccee8158d9c88d31e8e2
Fix pip install --upgrade 'twisted>=af8fe78542a6f2bf2235ccee8158d9c88d31e8e2'

References