CVE-2014-9720
24.01.2020, 18:15
Tornado before 3.2.2 sends arbitrary responses that contain a fixed CSRF token and may be sent with HTTP compression, which makes it easier for remote attackers to conduct a BREACH attack and determine this token via a series of crafted requests.Enginsight
Vendor | Product | Version |
---|---|---|
tornadoweb | tornado | 𝑥 < 3.2.2 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
References