CVE-2014-9720

MEDIUM

Tornado < 3.2.2 - Observable Discrepancy via BREACH Attack

Title source: llm
STIX 2.1

Description

Tornado before 3.2.2 sends arbitrary responses that contain a fixed CSRF token and may be sent with HTTP compression, which makes it easier for remote attackers to conduct a BREACH attack and determine this token via a series of crafted requests.

References (5)

Core 5
Core References
Mailing List, Patch, Third Party Advisory x_refsource_misc
http://openwall.com/lists/oss-security/2015/05/19/4
Release Notes, Vendor Advisory x_refsource_misc
http://www.tornadoweb.org/en/stable/releases/v3.2.2.html
Issue Tracking, Patch, Third Party Advisory x_refsource_misc
https://bugzilla.novell.com/show_bug.cgi?id=930362
Issue Tracking, Patch, Third Party Advisory x_refsource_misc
https://bugzilla.redhat.com/show_bug.cgi?id=1222816

Scores

CVSS v3 6.5
EPSS 0.0249
EPSS Percentile 82.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

Details

CWE
CWE-203
Status published
Products (2)
pypi/tornado 0 - 3.2.2PyPI
tornadoweb/tornado < 3.2.2
Published Jan 24, 2020
Tracked Since Feb 18, 2026