CVE-2014-9720
MEDIUMTornado < 3.2.2 - Observable Discrepancy via BREACH Attack
Title source: llmDescription
Tornado before 3.2.2 sends arbitrary responses that contain a fixed CSRF token and may be sent with HTTP compression, which makes it easier for remote attackers to conduct a BREACH attack and determine this token via a series of crafted requests.
References (5)
Core 5
Core References
Mailing List, Patch, Third Party Advisory x_refsource_misc
http://openwall.com/lists/oss-security/2015/05/19/4
Release Notes, Vendor Advisory x_refsource_misc
http://www.tornadoweb.org/en/stable/releases/v3.2.2.html
Patch x_refsource_misc
https://github.com/tornadoweb/tornado/commit/1c36307463b1e8affae100bf9386948e6c1b2308
Issue Tracking, Patch, Third Party Advisory x_refsource_misc
https://bugzilla.novell.com/show_bug.cgi?id=930362
Issue Tracking, Patch, Third Party Advisory x_refsource_misc
https://bugzilla.redhat.com/show_bug.cgi?id=1222816
Scores
CVSS v3
6.5
EPSS
0.0249
EPSS Percentile
82.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Details
CWE
CWE-203
Status
published
Products (2)
pypi/tornado
0 - 3.2.2PyPI
tornadoweb/tornado
< 3.2.2
Published
Jan 24, 2020
Tracked Since
Feb 18, 2026