Description
twisted is an event-driven networking engine written in Python. In affected versions twisted exposes cookies and authorization headers when following cross-origin redirects. This issue is present in the `twited.web.RedirectAgent` and `twisted.web. BrowserLikeRedirectAgent` functions. Users are advised to upgrade. There are no known workarounds.
Remediation
References
Related Vulnerabilities
WordPress Plugin IMPress for IDX Broker Unspecified Vulnerability (2.5.11)
Resin Application Server Other Vulnerability (CVE-2012-2967)
WordPress Plugin NextGEN Gallery-WordPress Gallery PHP Object Injection (3.1.5)
WordPress Plugin Wordfence Security-Firewall & Malware Scan Cross-Site Scripting (3.8.1)