QID 997078
Date Published: 2024-02-02
QID 997078: Python (Pip) Security Update for tornado (GHSA-8vpw-mgpf-mpvv)
Tornado before 3.2.2 sends arbitrary responses that contain a fixed CSRF token and may be sent with HTTP compression, which makes it easier for remote attackers to conduct a BREACH attack and determine this token via a series of crafted requests.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-8vpw-mgpf-mpvv for updates and patch information.
Vendor References
- GHSA-8vpw-mgpf-mpvv -
github.com/advisories/GHSA-8vpw-mgpf-mpvv
CVEs related to QID 997078
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-8vpw-mgpf-mpvv | tornado |
|