PT-2023-11359 · Unknown · Onshift Turbogears

CVE-2019-25101

·

Publicado

2023-02-04

·

Atualizado

2026-06-29

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OnShift TurboGears version 1.0.11.10
Description A critical vulnerability has been found in OnShift TurboGears, affecting an unknown part of the file turbogears/controllers.py of the component HTTP Header Handler. The manipulation leads to http response splitting, and it is possible to initiate the attack remotely.
Recommendations For OnShift TurboGears version 1.0.11.10, upgrade to version 1.0.11.11 to address this issue. As a temporary workaround, consider restricting access to the HTTP Header Handler component until the patch is applied.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-25101
GHSA-8Q38-W56M-QQ2C
PYSEC-2026-556

Produtos afetados

Onshift Turbogears